← Krajowa Izba Rozliczeniowa S.A. (KIR) cases
Bugzilla #1525082
Policy Compliance
Ernst & Young Poland: KIR OCSP "unknown" status for revoked certificate
RESOLVED
INVALID
Krajowa Izba Rozliczeniowa S.A. (KIR)
AI Summary
The case involves Krajowa Izba Rozliczeniowa S.A. (KIR) and their handling of OCSP responses for revoked certificates. KIR's auditor, T-Systems, recommended maintaining an 'unknown' status for OCSP responses until certificates are delivered to customers, which raised compliance concerns with WebTrust standards. The discussion highlighted the distinction between qualified and non-qualified certificates, with the latter now aligned with WebTrust. Ultimately, the bug was resolved as invalid due to the clarification that qualified certificates are out of scope for Mozilla's root store policy.
Chronology
- Initial report of OCSP status issue
- Clarification provided regarding auditor recommendations
- Bug closed as invalid
Participants
Wayne Thayer
Ben Wilson
Piotr Grabowski
Ryan Sleevi
External References
Similar Local Cases
SwissSign: BRs require full annual audits
Sectigo: Missing Changelog in CPS
Amazon Trust Services: CP/CPS does not specify key compromise methods
DigiCert: Inconsistent EV audits
GoDaddy: Non-BR-Compliant Certificate Issuance
PKIoverheid: Compliance issues CIBG TLS certificates
QuoVadis: Recap of BR Compliance in 2018 issuance by external subCAs
Izenpe: Non-BR-Compliant Certificate Issuance