← EDICOM cases
Bugzilla #1397830 Policy Compliance

EDICOM: Signing SHA-1 OCSP responses with unconstrained certificate

RESOLVED FIXED EDICOM
AI Summary

EDICOM was found to be signing OCSP responses with SHA-1 using an unconstrained certificate, violating Mozilla's Root Store Policy. Despite previous communications stating they would cease this practice, technical challenges prevented them from disabling SHA-1. Consequently, EDICOM decided to stop supporting their old Certification Authority Root and initiated the process to remove it from the trusted PKI Root. The case has been resolved with a plan to remove the old root certificate.

Model: gpt-4o-mini Generated: 2026-06-13 17:08 UTC Confidence: 1.00
Chronology
  1. Bug reported regarding SHA-1 OCSP responses.
  2. EDICOM acknowledged technical issues with disabling SHA-1.
  3. Request filed to remove the old ACEDICOM root certificate.
  4. Discussion on removing the Security Issue flag.
Participants
Andrew Ayer Raúl Santisteban Kathleen Wilson Gervase Markham Ryan Sleevi
Similar Local Cases
#1391066 RESOLVED Policy Compliance Opened 2017-08-16 · Closed 2023-02-22 · 61% similar
SwissSign: Non-BR-Compliant Certificate Issuance
#1391054 RESOLVED Policy Compliance Opened 2017-08-16 · Closed 2023-02-22 · 61% similar
Izenpe: Non-BR-Compliant Certificate Issuance
#1374381 RESOLVED Policy Compliance Opened 2017-06-19 · Closed 2023-02-22 · 60% similar
SwissSign: BRs require full annual audits
#1705904 RESOLVED Policy Compliance Opened 2021-04-17 · Closed 2023-02-22 · 56% similar
KIR S.A.: CP/CPS contains noncompliant DV method, does not specify CAA domains
#1705480 RESOLVED Policy Compliance Opened 2021-04-15 · Closed 2023-02-22 · 55% similar
SECOM: CP/CPS does not clearly specify domain validation methods
#1596949 RESOLVED Policy Compliance Opened 2019-11-15 · Closed 2023-02-22 · 55% similar
FNMT: CP/CPS lack CAA processing details
#1391064 RESOLVED Policy Compliance Opened 2017-08-16 · Closed 2023-02-22 · 55% similar
SECOM: Non-BR-Compliant Certificate Issuance
#1713976 RESOLVED Policy Compliance Opened 2021-06-02 · Closed 2023-02-22 · 55% similar
Amazon Trust Services: CP/CPS does not specify key compromise methods

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action