Closed Bug 2056663 Opened 1 month ago Closed 1 month ago

DigiCert: EVG CA profile compliance

Categories

(CA Program :: CA Certificate Compliance, task)

Tracking

(Not tracked)

RESOLVED INVALID

People

(Reporter: dcbugzillaresponse, Assigned: dcbugzillaresponse)

Details

(Whiteboard: [ca-compliance] [policy-failure] Next update 2026-08-02)

Preliminary Incident Report

Summary

  • Incident description: A third party reports that a DigiCert ICA profile is non-compliant with an interpretation of the EVG requirements.
  • Relevant policies: Guidelines for the Issuance and Management of Extended Validation Certificates (v1.8.0, effective 2022-11-30), Section 9.2.
  • Source of incident disclosure: Third party reported.

DigiCert is preparing its full incident report and will post it on or before 2026-08-02. We request a Next Update be set for 2026-08-02.

Flags: needinfo?(incident-reporting)
Assignee: nobody → dcbugzillaresponse
Status: UNCONFIRMED → ASSIGNED
Ever confirmed: true
Flags: needinfo?(incident-reporting)
Whiteboard: [ca-compliance] [policy-failure] Next update 2026-08-02

DigiCert received a Certificate Problem Report (CPR) that postulated that the “DigiCert QuoVadis G3 Qualified TLS RSA4096 SHA256 2023 CA1” SubCA violates the EV Guidelines (EVG). It specifically identifies Section 9.8.2 in v1.8.0 in effect at the time of issuance (the text of which is now found in Section 7.1.2.2 of the current EVG following a realignment in Ballot SC065 in 2024).

The CPR contends that because the SubCA 1) operates under the EVG; and 2) includes a organizationIdentifier; then 3) it must have a cabfOrganizationIdentifier.

This topic has been addressed directly within the CA/B Forum, most recently in February, 2026 following a request for clarification to the CABF from an EU-based conformity assessment body:

Specific Question: Does the following requirement from the EV Guidelines apply to Subordinate CA Certificates, or is it strictly reserved for Subscriber (End-Entity) Certificates?

"This extension [cabfOrganizationIdentifier] MAY be present. If the Subject:organizationIdentifier field is present, this extension MUST be present."

Following internal discussion within the CABF, documented in the internal discussion list used to determine answers to external questions, a response was formulated with input from a range of CABF members, the authors of the EVG. The following formal response was provided to the auditor by the CABF Chair on February 9, 2026:

The requirements for the presence and contents of extensions in EV CA certificates are indicated in section 7.1.4.3. The requirements for extensions in section 7.1.2 (where the OrgId extension is listed alongside the SAN extension) are applicable only to Subscriber Certificates.

The formal interpretation of the CABF is that this section applies “only to Subscriber Certificates” and not to SubCAs. We assert that the certificate was not mis-issued and request this Bug be closed as INVALID.

The TLS BR previously underwent a profiles cleanup with Ballot SC062 in 2023. Clarifications of this kind are overdue to the EVG, and this CPR is a good occasion to start such an effort. If the community or the Root Programs consider it useful, DigiCert will propose a CABF ballot to clarify the scope and profile provisions of EVG Section 7.1. We welcome collaboration, including from other CAs and QTSPs operating European eIDAS Qualified hierarchies.

Flags: needinfo?(incident-reporting)

It has been proposed that we close this bug as INVALID, which we will schedule to occur on or about August 3, 2026. If members of the community have additional information or believe there are other considerations that should be taken into account before closure, we welcome those comments.

Separately, we agree that this would be a worthwhile topic for the CA/B Forum to clarify in a future ballot to remove any ambiguity in the EV Guidelines regarding the applicability of such requirement to Subordinate CA Certificates.

Flags: needinfo?(incident-reporting)
Status: ASSIGNED → RESOLVED
Closed: 1 month ago
Resolution: --- → INVALID
You need to log in before you can comment on or make changes to this bug.