← Asseco Data Systems S.A. cases
Bugzilla #1717034
Policy Compliance
Asseco DS / Certum: CPS does not refer to BR domain validation methods
RESOLVED
FIXED
Asseco Data Systems S.A.
AI Summary
The case addresses a compliance issue with Certum's Certificate Practice Statement (CPS), which did not reference the appropriate Baseline Requirements (BR) domain validation methods. This was identified in a report by a third party, leading Certum to acknowledge the oversight and commit to updating their CPS to include the necessary references. The resolution involved a thorough analysis of the CPS and a commitment to publish an updated version that aligns with compliance standards.
Chronology
- Bug created after a compliance issue was reported.
- Certum updated their CPS to include references to relevant BR sections.
Participants
George [:fozzie]
Aleksandra Kurosz
Ryan Sleevi
B Wilson
External References
Similar Local Cases
Disig: CPS does not refer to BR domain validation methods
Asseco DS / Certum: Cross-Signed non-EV-audited root with an EV-enabled root
Asseco DS / Certum: Use of forbidden subjectPublicKeyInfo algorithm
Apple: Intermediate CA certificates omitted from audit statement
SECOM: CP/CPS does not clearly specify domain validation methods
KIR S.A.: CP/CPS contains noncompliant DV method, does not specify CAA domains
Amazon Trust Services: Forbidden Domain Validation Method 3.2.2.4.6
Sectigo: Missing Changelog in CPS