TWCA: Policy OID not set to indicate the assurance level to the issued certs
The case involves Taiwan-CA Inc. (TWCA) disclosing a compliance issue regarding the absence of Policy OIDs in certain issued certificates, which are necessary to indicate the assurance level as per CA/B Forum Baseline Requirements. TWCA became aware of the issue through discussions on the Mozilla Dev Security Policy (MDSP) mailing list and subsequent investigations. They confirmed that the certificates in question were issued before the introduction of the OID requirement and thus were not in violation of the Baseline Requirements. TWCA has since updated their practices to ensure compliance and is revising their Certificate Policy/Certificate Practice Statement (CP/CPS) to reflect these changes. The resolution status is marked as fixed.
- TWCA acknowledged the compliance issue and began investigating the absence of Policy OIDs.
- TWCA completed CPS changes related to the issue and is awaiting government approval.
- Community commenter — Reported the absence of Policy OIDs in certificates issued by TWCA.
- Taiwan-CA Inc. (TWCA) — Confirmed the issue and stated that the certificates were compliant as they were issued before the OID requirement.
- Taiwan-CA Inc. (TWCA) — Announced that the new CP and CPS have been posted to their official repository.