← e-tugra cases
Bugzilla #1716902
Technical Compliance
E-Tugra: Forbidden Domain Validation Method 3.2.2.4.6
RESOLVED
FIXED
e-tugra
AI Summary
E-Tugra reported that they had previously used the domain validation method 3.2.2.4.6 but ceased its use in June 2020. The issue arose when it was discovered that this method was still referenced in their Certificate Policy Statement (CPS). E-Tugra confirmed that no certificates had been issued using this method after June 2020 and has since updated their CPS to reflect this change. They have implemented enhanced procedures for compliance monitoring and regular updates to their policies to prevent similar issues in the future.
Chronology
- Validation method 3.2.2.4.6 was restricted.
- E-Tugra became aware of the issue with their CPS.
- E-Tugra updated their CPS to version 4.8.
Participants
Davut Tokgöz
George [:fozzie]
Ben Wilson
Matthias
Ryan Sleevi
External References
Similar Local Cases
Asseco DS / Certum: Forward dating certificates (notBefore in the future)
Telekom Security: Finding in 2020 ETSI-Audit regarding weekly review of changes to configurations
Sectigo: Reseller ZeroSSL and Private Key Generation
Let's Encrypt: Failure to audit log subscriber certificate OCSP updates
Sectigo: Late termination of privileged access to Certificate Systems
Visa: Non-BR-Compliant OCSP Responders
Firmaprofesional: 2022 - Define Device Obsolescence Process
Entrust: CRLs and OCSP responses not issued as specified in the CPS