← Apple Inc. cases
Bugzilla #1724528
Policy Compliance
Apple: Intermediate CA certificates omitted from audit statement
RESOLVED
FIXED
Apple Inc.
AI Summary
Apple Inc. reported an incident where three of its EV Sub-CAs were omitted from the recently issued WebTrust audit statement. The omission was identified following a notification from their root vendor, DigiCert, prompting an internal review. Apple confirmed that the omission was an unintended clerical error and that the audits had correctly covered the omitted CAs. Amended audit statements were subsequently issued and published. Apple has since updated its quality review procedures to prevent similar issues in the future.
Chronology
- Received notification of outdated audit statements
- Received and published amended audit report
Participants
Apple CA
Ryan Sleevi
B Wilson
External References
Similar Local Cases
Asseco DS / Certum: CPS does not refer to BR domain validation methods
Actalis: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy
Entrust: Improperly Verified Business Category
PKIoverheid: Missing Intermediate CA from audit statement
DigiCert: Inconsistent EV audits
NetLock: Cumulative report connected to EV verification
Sectigo / SSL.com: Late disclosure of updated SSL.com CP/CPS to CCADB
Sectigo: Missing Changelog in CPS