DocuSign/Keynectis: Outdated audit statements for Class 2 Primary CA
The bug was opened because there were no current audit statements in the CCADB for a specific DocuSign/Keynectis root certificate labeled “Class 2 Primary CA” (with the SHA-256 and SHA-1 values listed in the report). The reporter asked for a representative from the owning CA to comment with information about the root certificate and its audit statements, including when chaining SSL certificates expire. A DocuSign/Keynectis representative confirmed that the “Certplus Class 2 Primary CA” entry in the audit statement corresponds to the “Class 2 Primary CA” included in Mozilla’s Root CA Program for DocuSign. The reporter then reviewed the CCADB audit statement table and concluded the audit row was intended to cover the “Class 2 Primary CA,” and that the non-revoked, non-technically-constrained subCAs were audited according to the expected criteria. The bug was closed as resolved after the reporter planned to update the audit statement information for the root certificate in the CCADB and exchange email with the auditor. The reporter also noted that Mozilla is rejecting audit statements that lack required information such as SHA-256 fingerprints of the root and intermediate certs in scope.
- A CCADB compliance issue was reported for a DocuSign/Keynectis Class 2 Primary CA root due to missing or outdated audit statement coverage.
- DocuSign/Keynectis confirmed the audit statement entry corresponds to the Mozilla-included Class 2 Primary CA root.
- The CCADB audit statement information was reviewed and the bug was closed as resolved with planned CCADB updates.
- Community commenter — Reported that there were no current audit statements for the specified “Class 2 Primary CA” root and asked whether the root should be removed from NSS if it is no longer audited.
- Community commenter — Requested a representative from DocuSign/Keynectis to provide details about the root certificate, its audit statements, and SSL certificate expiry timing.
- Docusign representative — Confirmed that the “Certplus Class 2 Primary CA” labeled in the audit statement is the same “Class 2 Primary CA” included in Mozilla’s Root CA Program for DocuSign.
- Community commenter — Provided a CCADB audit statement link, explained how the audit table row appears to refer to the Class 2 Primary CA, stated that subCAs were audited as expected, and said she would close the bug as resolved and update the CCADB audit statement information.