Camerfirma: MULTICERT Misissuance and missing audits
The case involves MULTICERT's misissuance of 174 certificates due to invalid QCStatements, which violated the syntax of the qcStatements extension. Additionally, it was discovered that the MULTICERT SSL Certification Authority 001 was not included in the scope of the required audits, leading to compliance issues. The audit for MULTICERT did not cover all necessary periods, resulting in a gap that was only addressed through a memo from the auditor. Despite efforts to remediate the situation, including stopping certificate issuance and reissuing affected certificates, concerns about compliance remain unresolved.
- Misissuance reported by Ryan Sleevi.
- MULTICERT provides audit attestation letter.
- Incident report detailing actions taken by MULTICERT.
- Discussion on audit gaps and compliance.
- New audit reports submitted.
- Concerns raised about audit compliance.
- Summary of unresolved compliance issues.