← Amazon Trust Services cases
Bugzilla #1713978
Policy Compliance
Amazon Trust Services: Forbidden Domain Validation Method 3.2.2.4.6
RESOLVED
FIXED
Amazon Trust Services
AI Summary
The case involves Amazon Trust Services' use of a domain validation method (3.2.2.4.6) that is prohibited by the Baseline Requirements. Concerns were raised regarding the clarity and compliance of their Certification Practice Statement (CPS) and Certification Policy (CP). Amazon acknowledged the feedback and committed to updating their documents to ensure compliance. By July 30, 2021, they planned to clarify their practices regarding validation methods. The issue was resolved when updated CP and CPS documents were published on July 23, 2021.
Chronology
- Initial report of the forbidden domain validation method.
- Amazon committed to updating their CP and CPS.
- Amazon published updated CP and CPS documents.
Participants
Andrew Ayer
Trevoli (Amazon Trust Services)
Ryan Sleevi
External References
Similar Local Cases
Amazon Trust Services: CP/CPS does not specify key compromise methods
SECOM: CP/CPS does not clearly specify domain validation methods
FNMT: CP/CPS lack CAA processing details
KIR S.A.: CP/CPS contains noncompliant DV method, does not specify CAA domains
Amazon Trust Services - BR Self Assessment and CP/CPS Updates
GoDaddy: inconsistent disclosure of externally-operated intermediate
PKIoverheid: KPN CPS lacks CPR problem reporting instructions
EDICOM: Signing SHA-1 OCSP responses with unconstrained certificate