You've given a detailed rundown like you've been following, so what is your sense about the resignation? Did the guy resign willingly, or is Digicert the kind of management that likely scapegoated him?
He assumed personal responsibility rather than institutional. At the time, everyone in the community expressed alarm that that happened, because 1) and this is obvious, there's no way a single guy would be responsible for the entire fallout and 2) because it sets a bad precedent about what companies can do with their PoC wrt web PKI. It also meant a loss in institutional knowledge about how things worked.
Do you have any resources regarding the resignation I could read?