← Krajowa Izba Rozliczeniowa S.A. (KIR) cases
Bugzilla #1525082 Policy Compliance

Ernst & Young Poland: KIR OCSP "unknown" status for revoked certificate

RESOLVED INVALID Krajowa Izba Rozliczeniowa S.A. (KIR)
AI Summary

The case involves Krajowa Izba Rozliczeniowa S.A. (KIR) and their handling of OCSP responses for revoked certificates. KIR's auditor, T-Systems, recommended maintaining an 'unknown' status for OCSP responses until certificates are delivered to customers, which raised compliance concerns with WebTrust standards. The discussion highlighted the distinction between qualified and non-qualified certificates, with the latter now aligned with WebTrust. Ultimately, the bug was resolved as invalid due to the clarification that qualified certificates are out of scope for Mozilla's root store policy.

Model: gpt-4o-mini Generated: 2026-06-13 18:02 UTC Confidence: 0.90
Chronology
  1. Initial report of OCSP status issue
  2. Clarification provided regarding auditor recommendations
  3. Bug closed as invalid
Participants
Wayne Thayer Ben Wilson Piotr Grabowski Ryan Sleevi
Similar Local Cases
#1705904 RESOLVED Policy Compliance Opened 2021-04-17 · Closed 2023-02-22 · 72% similar
KIR S.A.: CP/CPS contains noncompliant DV method, does not specify CAA domains
#1921595 RESOLVED Policy Compliance Opened 2024-09-28 · 60% similar
KIR: Intermediate CA - SZAFIR Trusted CA4 - Certificate Policies extension - non-compliance
#1586795 RESOLVED Policy Compliance Opened 2019-10-07 · Closed 2023-02-22 · 60% similar
NetLock: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy
#1672029 RESOLVED Policy Compliance Opened 2020-10-19 · Closed 2023-02-22 · 56% similar
Camerfirma: Failure to abide by Section 8 of Mozilla Policy: Unauthorized, improperly disclosed Subordinate CA
#1374381 RESOLVED Policy Compliance Opened 2017-06-19 · Closed 2023-02-22 · 56% similar
SwissSign: BRs require full annual audits
#1612389 RESOLVED Policy Compliance Opened 2020-01-30 · Closed 2023-02-22 · 55% similar
Google Trust Services: invalid curve-hash combination
#1680378 RESOLVED Policy Compliance Opened 2020-12-02 · Closed 2023-02-22 · 55% similar
NetLock: Replacement of enduser certificates after the EVGL 1.7.4 self-audit
#1738778 RESOLVED Policy Compliance Opened 2021-11-01 · Closed 2023-02-22 · 55% similar
TWCA: Policy OID not set to indicate the assurance level to the issued certs

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action