DocuSign/Keynectis: Non-BR-Compliant Certificate Issuance
This case involves DocuSign (Keynectis) disclosing non-compliance issues related to certificate issuance that did not meet the CA/Browser Forum Baseline Requirements. The CA became aware of the problems via a problem report on August 8, 2017, and confirmed that it had stopped issuing non-compliant certificates. A total of 47 certificates were identified with various issues, including invalid DNS names. The CA has since revoked all identified problematic certificates and implemented corrective measures to prevent future occurrences. The case is now resolved with all certificates revoked as of December 1, 2017.
- DocuSign became aware of non-compliance issues via a problem report.
- All identified non-compliant certificates were revoked.
- Mozilla representative — Initial report of compliance issues and request for information from DocuSign.
- Docusign representative — DocuSign confirmed they had stopped issuing non-compliant certificates.
- Docusign representative — Update on revocation of non-compliant certificates.
- Docusign representative — Detailed report on the identified issues and steps taken for resolution.
- Docusign representative — Confirmation that all problematic certificates have been revoked.