They could have revoked the certificates of companies not listed in the TRO. Instead revocations for _all_ customers were delayed by 3 days over the time limit [1].
Additionally, it seems more prudent to me that they should drop Allegius as a customer than make the guy resign. The current situation seems like if an issue occurs again then DigiCert will not revoke the certs according to the timeline they committed to (24h).
Additionally, it seems more prudent to me that they should drop Allegius as a customer than make the guy resign. The current situation seems like if an issue occurs again then DigiCert will not revoke the certs according to the timeline they committed to (24h).
[1]: https://bugzilla.mozilla.org/show_bug.cgi?id=1910805#c11