e-commerce monitoring GmbH: failure to maintain links to historic CP/CPS versions
This case concerns e-commerce monitoring GmbH’s failure to maintain working links to historic CP/CPS versions in its online policy documents. The issue was that broken links to historical CP/CPS versions were included in the documents, and the CA operator stated that the error was later rectified by linking historical versions on the website. The incident report states that MRSP § 3.3 bullet 7 sentence 2 was not followed, because relying parties could only review past versions to a limited extent or with additional effort. The thread includes a timeline showing that a broken link introduced in a 2020 CP version was not corrected in subsequent CP/CPS versions, and that additional linking errors were also made in later versions. The bug was marked RESOLVED with resolution WONTFIX. In a later comment, the CA also described broader process shortcomings and stated it had ceased issuance of TLS certificates according to CA/Browser Forum Requirements as an immediate action until full remediation, while continuing issuance solely based on EU Regulation (EU) No 910/2014 (QWACs), with interoperability testing excluded.
- e-commerce monitoring GmbH initiated an incident report regarding broken links to historic CP/CPS versions in its online policy documents.
- e-commerce monitoring GmbH described broader remediation actions and stated it had ceased CA/Browser Forum TLS issuance pending remediation.
- e-commerce monitoring GmbH — Daniel Zens stated that, as advised in another bug, e-commerce monitoring GmbH was preparing an incident report for not properly providing links to historic policy documents.
- Austriacard representative — The incident report was posted, stating that broken links to historical CP/CPS versions were included in documents and that the website was corrected by linking historical versions.
- e-commerce monitoring GmbH — Daniel Zens provided context about root program removal, acknowledged shortcomings (including reaction time), and stated an action plan was being rolled out; he also said ECM ceased CA/Browser Forum TLS issuance until full remediation and would issue only as QWACs, excluding interoperability testing.