← Disig, a.s. cases
Bugzilla #1717001
Policy Compliance
Disig: CPS does not refer to BR domain validation methods
RESOLVED
INVALID
Disig, a.s.
AI Summary
Disig's Certificate Practice Statement (CPS) was found to lack clear references to the Baseline Requirements (BR) for domain validation methods. This ambiguity was highlighted by a third-party report, prompting Disig to acknowledge the issue and commit to updating their CPS. The CA confirmed that the issuance of certificates was not affected by this problem and that a revised CPS was published to clarify compliance with the relevant requirements. The case was ultimately resolved as invalid due to the corrective actions taken.
Chronology
- Bug reported regarding CPS ambiguity
- Updated CPS published to address the issue
Participants
George [:fozzie]
Peter Miskovic
Ryan Sleevi
Brett Wilson
External References
Similar Local Cases
Disig: Failure to provide a preliminary report within 24 hours.
Asseco DS / Certum: CPS does not refer to BR domain validation methods
Microsoft PKI Services: Failure to disclose Unconstrained Intermediate within 7 Days
Amazon Trust Services: Forbidden Domain Validation Method 3.2.2.4.6
SECOM: CP/CPS does not clearly specify domain validation methods
KIR S.A.: CP/CPS contains noncompliant DV method, does not specify CAA domains
TWCA: Policy OID not set to indicate the assurance level to the issued certs
Sectigo: Missing Changelog in CPS