← Amazon Trust Services cases
Bugzilla #1521623 Technical Compliance

Amazon Trust Services: Failure to comply with RFC 5280

RESOLVED INVALID Amazon Trust Services
AI Summary

Amazon Trust Services reported a potential compliance issue with RFC 5280 regarding their certificates. Initial analysis indicated a low risk, as the primary use of the vulnerability was to redirect traffic, which is less of a concern given that the certificates are used solely on AWS resources. After further investigation, Amazon determined that the reported violation did not apply, as they do not perform any unicode encoding, thus concluding that revocation of certificates was unnecessary. The case was ultimately marked as invalid.

Model: gpt-4o-mini Generated: 2026-06-13 15:26 UTC Confidence: 0.90
Chronology
  1. Initial report of potential RFC 5280 compliance issue.
  2. Amazon clarifies that the reported violation does not apply.
  3. Discussion on the validity of the compliance issue.
  4. Confirmation that the encoding issue is not applicable.
Participants
Trevoli (Amazon Trust Services) Wayne Thayer (Fastly)
Similar Local Cases
#1746945 RESOLVED Technical Compliance Opened 2021-12-20 · Closed 2023-02-22 · 60% similar
Amazon Trust Services: Missing CAA Check For Test Website Certificates
#1914893 RESOLVED Technical Compliance Opened 2024-08-26 · Closed 2024-09-18 · 57% similar
Amazon Trust Services: CRL not DER-encoded
#1398240 RESOLVED Technical Compliance Opened 2017-09-08 · Closed 2023-02-22 · 39% similar
Firmaprofesional: Non-BR-Compliant OCSP Responders
#1015767 RESOLVED Technical Compliance Opened 2014-05-25 · Closed 2022-11-14 · 39% similar
startcom: still issuing < 2048 bit certificates
#1398261 RESOLVED Technical Compliance Opened 2017-09-08 · Closed 2023-02-22 · 38% similar
Visa: Non-BR-Compliant OCSP Responders
#1398246 RESOLVED Technical Compliance Opened 2017-09-08 · Closed 2023-02-22 · 38% similar
Consorci AOC: Non-BR-Compliant OCSP Responders
#1436173 RESOLVED Technical Compliance Opened 2018-02-06 · Closed 2023-02-22 · 38% similar
DigiCert: SCEE / Justica: Non-BR-Compliant Certificate Issuance
#1772644 RESOLVED Technical Compliance Opened 2022-06-04 · Closed 2023-02-22 · 38% similar
Apple: CRL issuance frequency deviates from CPS in some cases

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action