← e-commerce monitoring GmbH cases
Bugzilla #1897457 Repository Issue

e-commerce monitoring GmbH: failure to maintain links to historic CP/CPS versions

RESOLVED WONTFIX e-commerce monitoring GmbH
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns e-commerce monitoring GmbH’s failure to maintain working links to historic CP/CPS versions in its online policy documents. The issue was that broken links to historical CP/CPS versions were included in the documents, and the CA operator stated that the error was later rectified by linking historical versions on the website. The incident report states that MRSP § 3.3 bullet 7 sentence 2 was not followed, because relying parties could only review past versions to a limited extent or with additional effort. The thread includes a timeline showing that a broken link introduced in a 2020 CP version was not corrected in subsequent CP/CPS versions, and that additional linking errors were also made in later versions. The bug was marked RESOLVED with resolution WONTFIX. In a later comment, the CA also described broader process shortcomings and stated it had ceased issuance of TLS certificates according to CA/Browser Forum Requirements as an immediate action until full remediation, while continuing issuance solely based on EU Regulation (EU) No 910/2014 (QWACs), with interoperability testing excluded.

Model: gpt-5.4-nano Generated: 2026-06-13 21:26 UTC Revised: 2026-06-16 18:36 UTC Confidence: 0.86 4 comments
Chronology
  1. e-commerce monitoring GmbH initiated an incident report regarding broken links to historic CP/CPS versions in its online policy documents.
  2. e-commerce monitoring GmbH described broader remediation actions and stated it had ceased CA/Browser Forum TLS issuance pending remediation.
Thread Activity
  1. e-commerce monitoring GmbH — Daniel Zens stated that, as advised in another bug, e-commerce monitoring GmbH was preparing an incident report for not properly providing links to historic policy documents.
  2. Austriacard representative — The incident report was posted, stating that broken links to historical CP/CPS versions were included in documents and that the website was corrected by linking historical versions.
  3. e-commerce monitoring GmbH — Daniel Zens provided context about root program removal, acknowledged shortcomings (including reaction time), and stated an action plan was being rolled out; he also said ECM ceased CA/Browser Forum TLS issuance until full remediation and would issue only as QWACs, excluding interoperability testing.
Participants
e-commerce monitoring GmbH Community commenter Austriacard representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1957140 RESOLVED Repository Issue Opened 2025-03-28 · Closed 2025-08-11 · 59% similar
SSL.com: "unknown" OCSP response for issued certificates
#1572234 RESOLVED Self Reported Incident Repository Issue Opened 2019-08-07 · Closed 2023-02-22 · 59% similar
GoDaddy: cross certificate disclosure to CCADB
#1999241 RESOLVED Incident Repository Issue Opened 2025-11-10 · Closed 2025-12-24 · 59% similar
eMudhra emSign PKI Services : Delayed Publication of Issuing CA Certificates in CCADB
#1565494 RESOLVED Audit Finding Self Reported Incident Repository Issue Opened 2019-07-12 · Closed 2024-06-30 · 59% similar
CFCA: Missed annual CPS update publication on website in 2018
#1925293 RESOLVED Repository Issue Self Reported Incident Opened 2024-10-17 · Closed 2025-02-28 · 59% similar
Firmaprofesional: Incorrect publication of information for "Test Website - Revoked" URL in the CCADB.
#1455147 RESOLVED Ca Documents Repository Issue Opened 2018-04-18 · Closed 2023-02-22 · 59% similar
Camerfirma: Missing audit for Intermediate certificate
#2009543 RESOLVED Ca Certificate Compliance Incident Repository Issue Opened 2026-01-10 · Closed 2026-02-09 · 58% similar
Microsoft PKI Services: Improper Disclosure of CRLs – Does Not Match CA Subject
#1581183 RESOLVED Repository Issue Opened 2019-09-13 · Closed 2023-02-22 · 58% similar
Google Trust Services: CRL handling of expired certificates not fully compliant with RFC 5280 Section 3.3

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action