DigiCert disclosure of a cross-certificate intermediate with blank Subordinate CA Owner field
This case concerns a CCADB disclosure issue involving a cross-certificate intermediate that DigiCert disclosed under its CP/CPS, while Microsoft had also disclosed a certificate for the same subordinate key and subject under Microsoft’s CP/CPS. The report said the same key and subject appeared in both certificates and that someone had incorrectly disclosed an intermediate. DigiCert responded that it was investigating, then later said the disclosures were accurate and compliant and asked for the report to be closed as invalid. The reporter then pointed out that the Subordinate CA Owner field for the DigiCert certificate was blank and quoted CCADB policy requiring that field not be left blank unless the listed organization performs both private-key control and domain/IP validation. The thread ends with DigiCert’s position that the cross-certificates were revoked, not used for end-entity issuance, and would be included in the next DigiCert WebTrust audit, while the reporter maintained the disclosure was non-compliant.
- A DigiCert cross-certificate and a Microsoft certificate were identified as sharing the same key and subject.
- DigiCert said the certificates were cross-certificates, revoked, and would be included in the next DigiCert WebTrust audit.
- Mm representative — Reported that DigiCert and Microsoft had both disclosed an intermediate certificate for the same key and subject, and said someone had incorrectly disclosed an intermediate.
- DigiCert — DigiCert said it was investigating and would file a preliminary report as required by CCADB policy.
- DigiCert — DigiCert said the disclosures were accurate and compliant, requested closure as invalid, and explained its view of the cross-certificate lifecycle and audit treatment.
- Mm representative — Pointed out that the Subordinate CA Owner field was blank and cited CCADB policy as making the disclosure non-compliant.