Kamu SM: Non-BR-Compliant Certificate Issuance
The Government of Turkey's CA, Kamu Sertifikasyon Merkezi (Kamu SM), was found to have issued certificates that did not comply with the CA/Browser Forum's Baseline Requirements (BRs). The CA acknowledged the issues, which included the use of an old root certificate with insufficient entropy for serial numbers. The CA has since ceased issuing certificates from the problematic root and plans to transition to a new root that complies with the required standards. They provided a remediation plan and committed to regular updates regarding their compliance efforts. The case has been marked as resolved after the CA completed the necessary remediation steps.
- Kamu SM acknowledged non-compliance and outlined steps for remediation.
- Mozilla representative — Initial report of non-compliance issues with Kamu SM's certificates.
- Government of Turkey, Kamu Sertifikasyon Merkezi (Kamu SM) — Kamu SM expressed regret and explained the reasons for using the old root.
- Government of Turkey, Kamu Sertifikasyon Merkezi (Kamu SM) — Kamu SM provided a detailed remediation plan and confirmed cessation of issuing from the old root.
- Community commenter — Marked the issue as resolved after remediation steps were completed.