Amazon Trust Services: CP/CPS does not specify key compromise methods
The case involves Amazon Trust Services' failure to specify methods for demonstrating private key compromise in their Certificate Policy/Certificate Practice Statement (CP/CPS), as required by the Mozilla Root Store Policy. The issue was raised by a Mozilla representative, noting that the current CP/CPS did not comply with the specified requirements. Amazon acknowledged the issue and committed to updating their documents by July 30, 2021. They subsequently published updated CP and CPS documents on July 23, 2021, which addressed the issue. The bug was resolved as fixed after confirming the updates met compliance requirements.
- Amazon Trust Services published updated CP and CPS documents addressing the key compromise specification issue.
- Mm representative — Raised the issue regarding the lack of key compromise methods in Amazon's CP/CPS.
- DigiCert — Acknowledged the bug and stated plans to fix it by July 30, 2021.
- DigiCert — Confirmed the publication of updated CP and CPS documents that addressed the issue.
- DigiCert — Requested to resolve the bug as fixed.