← Amazon Trust Services cases
Bugzilla #1713976 Policy Compliance

Amazon Trust Services: CP/CPS does not specify key compromise methods

RESOLVED FIXED Amazon Trust Services
AI Summary

Amazon Trust Services was found to have a compliance issue regarding their Certificate Policy (CP) and Certificate Practice Statement (CPS), specifically that they did not specify methods for demonstrating private key compromise as required by Mozilla's Root Store Policy. The issue was acknowledged by Amazon, and they committed to updating their documents by July 30, 2021. Following the updates, it was noted that while some changes were made, further clarification was needed to fully meet compliance expectations. Ultimately, Amazon updated their CPS to include clearer instructions for reporting key compromise by August 20, 2021.

Model: gpt-4o-mini Generated: 2026-06-13 15:27 UTC Confidence: 1.00
Chronology
  1. Initial bug reported regarding CP/CPS compliance.
  2. Amazon Trust Services committed to updating CP/CPS.
  3. Amazon updated CPS to include preferred information for key compromise reporting.
Participants
Andrew Ayer Trevoli (Amazon Trust Services) Ben Wilson Ryan Sleevi
Similar Local Cases
#1713978 RESOLVED Policy Compliance Opened 2021-06-02 · Closed 2023-02-22 · 79% similar
Amazon Trust Services: Forbidden Domain Validation Method 3.2.2.4.6
#1688215 RESOLVED Policy Compliance Opened 2021-01-22 · Closed 2023-02-22 · 64% similar
Camerfirma: CP/CPS of Intesa Sanpaolo Sub-CA is Non-Compliant
#1705904 RESOLVED Policy Compliance Opened 2021-04-17 · Closed 2023-02-22 · 64% similar
KIR S.A.: CP/CPS contains noncompliant DV method, does not specify CAA domains
#1596949 RESOLVED Policy Compliance Opened 2019-11-15 · Closed 2023-02-22 · 62% similar
FNMT: CP/CPS lack CAA processing details
#1454102 RESOLVED Policy Compliance Opened 2018-04-13 · Closed 2022-12-08 · 61% similar
Amazon Trust Services - BR Self Assessment and CP/CPS Updates
#1705480 RESOLVED Policy Compliance Opened 2021-04-15 · Closed 2023-02-22 · 60% similar
SECOM: CP/CPS does not clearly specify domain validation methods
#1596923 RESOLVED Policy Compliance Opened 2019-11-15 · Closed 2024-06-30 · 58% similar
PKIoverheid: KPN CPS lacks CPR problem reporting instructions
#1567061 RESOLVED Policy Compliance Opened 2019-07-18 · Closed 2023-02-22 · 58% similar
GoDaddy: inconsistent disclosure of externally-operated intermediate

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action