← Amazon Trust Services cases
Bugzilla #2063908 Ca Certificate Compliance Self Reported Incident Policy Document Issue Cp Cps Document

Amazon Trust Services self-reports CP/CPS policy-language gap

ASSIGNED Amazon Trust Services
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Amazon Trust Services reported that its CP/CPS did not explicitly state adherence to the latest published version of the Chrome Root Program Policy and the CCADB Policy, as required by Chrome Root Program Policy v1.8 Section 1.1.3. ATS said its existing CP/CPS language said it aligns with the Chrome Root Program Policy, but did not use the phrase "latest published version" and did not mention the CCADB Policy. ATS identified the issue after reviewing similar disclosures from Google Trust Services and Let's Encrypt. It said it was publishing a corrected CP/CPS section and self-reporting the incident for transparency. ATS later said it published CP/CPS v2.7 on 2026-08-19 and was preparing the final report within the stated timeframe.

Model: gpt-5.4-mini Generated: 2026-08-26 10:52 UTC Confidence: 0.98 2 comments
Chronology
  1. ATS identified a CP/CPS language gap regarding explicit adherence to the latest published Chrome Root Program Policy and the CCADB Policy.
  2. ATS published CP/CPS version 2.7 with corrected language.
  3. ATS said it was actively preparing the final report for the incident.
Thread Activity
  1. Amazon representative — ATS opened a preliminary incident report describing the CP/CPS gap, said it was self-reporting, and said it would publish a full incident report within 14 days.
  2. Amazon representative — ATS said it had published CP/CPS v2.7 and was on track to publish the final report within the stipulated timeframe.
Participants
Amazon representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1569266 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-07-26 · Closed 2023-02-22 · 79% similar
Amazon Trust Services: No Space In Private Organization
#1525710 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-02-06 · Closed 2023-02-22 · 78% similar
Amazon Trust Services: Test revoked certificates with invalid validity period
#2062418 NEW Ca Certificate Compliance Self Reported Incident Policy Document Issue Cp Cps Document Opened 2026-08-10 Still Open · 75% similar
Let's Encrypt: CPS missing root program attestation
#2038351 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-05-08 Still Open · 70% similar
Let's Encrypt: Gen Y Cross-Certified Subordinate CAs missing serverAuth EKU
#1942651 RESOLVED Self Reported Incident Policy Document Issue Opened 2025-01-20 · Closed 2025-02-14 · 70% similar
Sectigo / SSL.com: Late disclosure of updated SSL.com CP/CPS to CCADB
#1962829 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Policy Document Issue Opened 2025-04-26 · Closed 2026-04-26 · 70% similar
Microsoft PKI Services: Policy document bug
#1973236 RESOLVED Incident Policy Document Issue Self Reported Incident Opened 2025-06-20 · Closed 2025-07-09 · 70% similar
ANF AC: Delayed Disclosure of Updated Policy Documents in CCADB
#1746945 RESOLVED Certificate Misissuance Self Reported Incident Opened 2021-12-20 · Closed 2023-02-22 · 70% similar
Amazon Trust Services: Missing CAA Check For Test Website Certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action