← DarkMatter LLC cases
Bugzilla #1391063
Policy Compliance
QuoVadis: Non-BR-Compliant Certificate Issuance
RESOLVED
FIXED
DarkMatter LLC
AI Summary
QuoVadis faced issues with non-Baseline Requirements (BR) compliant certificate issuance, including metadata-only subject fields and short/sequential serial numbers. The CA was required to provide a remediation plan and confirm that problematic certificates would be revoked or replaced. QuoVadis acknowledged the issues and outlined steps to prevent recurrence, including implementing filters in their certificate management system. All affected certificates were eventually revoked, and the CA transitioned to a new system to enhance compliance.
Chronology
- Bug reported regarding non-compliance.
- New filters for OU fields deployed.
- Majority of affected certificates replaced.
- All affected certificates revoked.
Participants
Stephen Davidson
Kathleen Wilson
Ryan Sleevi
External References
Similar Local Cases
QuoVadis: Recap of BR Compliance in 2018 issuance by external subCAs
Entrust: Non-BR-Compliant Certificate Issuance
GoDaddy: Non-BR-Compliant Certificate Issuance
SwissSign: Non-BR-Compliant Certificate Issuance
Izenpe: Non-BR-Compliant Certificate Issuance
Staat der Nederlandend / PKIoverheid: Non-BR-Compliant Certificate Issuance
SECOM: Non-BR-Compliant Certificate Issuance
Actalis: Non-BR-Compliant Certificate Issuance