Amazon Trust Services: Failure to comply with RFC 5280
The bug was opened after Amazon Trust Services was notified that it had issued certificates that did not comply with RFC 5280. In the initial response, Amazon Trust Services said it had performed an initial impact analysis and determined the potential impact was low, and it planned to reach out to customers to revoke certificates while its investigation progressed. Amazon Trust Services later stated that a more thorough analysis showed that the specific reported violation (RFC 8250 section 7.2) did not apply because it does not perform Unicode encoding and the certificates are not IDNs. After further discussion, the reporter asked for an explanation to support closing the bug, and Amazon Trust Services confirmed the issue was related to an IDNA2008 encoding discussion and that it was not a clearly applicable violation. The bug was ultimately marked RESOLVED with resolution INVALID.
- Amazon Trust Services was notified of an alleged RFC 5280 non-compliance issue affecting certificates it issued.
- Amazon Trust Services completed a more thorough analysis and concluded the reported RFC 8250 section 7.2 violation did not apply, so it would not revoke certificates.
- Amazon Trust Services confirmed the issue was related to IDNA2008 encoding and that it was not a clearly applicable violation.
- DigiCert — Reported that Mozilla notified Amazon Trust Services of certificates allegedly not complying with RFC 5280 and said it would reach out to customers to revoke while investigating.
- Fastly representative — Asked for enough information for Mozilla to assess the risk as soon as possible.
- DigiCert — Explained that RFC 8250 section 7.2 did not apply because Amazon Trust Services does not perform Unicode encoding and the certificates are not IDNs, and stated it would not revoke certificates.
- Fastly representative — Asked for clarification of what was reported and how the analysis concluded the RFC 5280 section did not apply.
- Fastly representative — Indicated it might be related to an IDNA2008 encoding discussion and asked for confirmation that it was invalid because it was not clearly a Mozilla policy violation.
- DigiCert — Confirmed it was related to the IDNA2008 encoding discussion and stated that during investigation it realized it was not performing the encoding.