← DarkMatter LLC cases
Bugzilla #1650234
Policy Compliance
PKIoverheid / QuoVadis: CPS inconsistencies
RESOLVED
FIXED
DarkMatter LLC
AI Summary
This case addresses inconsistencies found in the Certification Practice Statement (CPS) of QuoVadis, a delegated CA under PKIoverheid. Key issues included unclear instructions for reporting certificate problems, limitations on who can request revocation, and inadequate contact information for third parties. The CA acknowledged the report and committed to improving the CPS language and clarity. Subsequent updates to the CPS aimed to address these concerns, and the case was ultimately resolved with the implementation of changes.
Chronology
- Initial report of CPS inconsistencies submitted.
- Discussion on the validity of the reported issues and acknowledgment of the need for clarity.
- Updated CPS released with improved language regarding certificate problem reporting.
- Final confirmation of CPS updates and request for closure of the bug.
Participants
Matthias
Stephen Davidson
Jeremy Rowley
Ryan Sleevi
Brenda Bernal
Ben Wilson
External References
Similar Local Cases
PKIoverheid / QuoVadis: CPS inconsistencies
QuoVadis: Recap of BR Compliance in 2018 issuance by external subCAs
QuoVadis: Non-BR-Compliant Certificate Issuance
QuoVadis: Unconstrained CAs missing audits
DigiCert: Inconsistent EV audits
Amazon Trust Services: CP/CPS does not specify key compromise methods
KIR S.A.: CP/CPS contains noncompliant DV method, does not specify CAA domains
Google Trust Services: Signing SHA-1 Hash for existing CA certificate with changes in Key Usage