← Krajowa Izba Rozliczeniowa S.A. (KIR) cases
Bugzilla #1705904 Policy Document Issue Self Reported Incident

KIR S.A.: CP/CPS contains noncompliant DV method, does not specify CAA domains

RESOLVED FIXED Krajowa Izba Rozliczeniowa S.A. (KIR)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Krajowa Izba Rozliczeniowa S.A. (KIR) disclosed a compliance issue regarding its Certification Practice Statement (CP/CPS), which failed to specify recognized CAA domains and included a noncompliant domain validation method. The issue was identified through a third-party report, prompting KIR to investigate and confirm the non-compliance. KIR has committed to updating its CP/CPS to address these deficiencies and has initiated a corrective action plan, including a timeline for updates and a review of its compliance processes. The updated CP/CPS was published on May 1, 2021, incorporating necessary changes.

Model: gpt-4o-mini Generated: 2026-06-13 21:13 UTC Revised: 2026-06-16 19:13 UTC Confidence: 0.85 29 comments
Chronology
  1. KIR S.A. disclosed issues in its CP/CPS regarding domain validation and CAA records.
  2. KIR S.A. published an updated CP/CPS addressing the identified compliance issues.
Thread Activity
  1. Mm representative — KIR S.A. has disclosed the following CP/CPS that does not specify recognized CAA domains.
  2. Kir representative — KIR S.A. confirmed the issue and began an investigation.
  3. Kir representative — KIR S.A. provided a detailed timeline of actions taken in response to the compliance issue.
  4. Kir representative — Updated CP/CPS has been published, now including a section on CAA Records Processing.
Participants
Community commenter
Similar Local Cases
#1705832 RESOLVED Incident Self Reported Incident Opened 2021-04-16 · Closed 2023-02-22 · 79% similar
KIR S.A.: DV certificates with locality name, organization name and stateOrProvinceName
#1671410 RESOLVED Self Reported Incident Opened 2020-10-15 · Closed 2024-06-30 · 78% similar
IdenTrust: Inconsistent Disclosure of Externally-Operated Intermediate
#1567062 RESOLVED Self Reported Incident Audit Finding Opened 2019-07-18 · Closed 2023-02-22 · 75% similar
Asseco DS / Certum: inconsistent disclosure of externally-operated intermediate
#1921573 RESOLVED Self Reported Incident Policy Document Issue Opened 2024-09-27 · Closed 2024-11-06 · 72% similar
Let's Encrypt: No Meaningful Subject Distinguished Name
#1714628 RESOLVED Incident Self Reported Incident Opened 2021-06-04 · Closed 2023-02-22 · 72% similar
Sectigo: Forbidden Domain Validation Method
#1886876 RESOLVED Self Reported Incident Policy Document Issue Opened 2024-03-21 · Closed 2024-04-17 · 71% similar
Let's Encrypt: keyCompromise key blocking deviation from CP/CPS
#1948600 RESOLVED Self Reported Incident Policy Document Issue Opened 2025-02-17 · Closed 2025-07-01 · 70% similar
IZENPE: Outdated CPS for Izenpe Root
#1973236 RESOLVED Incident Policy Document Issue Self Reported Incident Opened 2025-06-20 · Closed 2025-07-09 · 70% similar
ANF AC: Delayed Disclosure of Updated Policy Documents in CCADB

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action