← Amazon Trust Services cases
Bugzilla #2063908 Ca Certificate Compliance Incident Self Reported Incident Policy Document Issue Cp Cps Document

Amazon Trust Services self-reports CP/CPS omission of CCADB Policy adherence language; closure pending

RESOLVED FIXED Amazon Trust Services
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Amazon Trust Services self-reported that its CP/CPS Section 1.1 did not explicitly state adherence to the CCADB Policy, as required by Chrome Root Program Policy v1.8 Section 1.1.3. The issue affected CP/CPS versions v2.4 through v2.6 and was limited to the wording of the document; ATS stated that its operational practices already conformed to the policy and that no certificates were affected. ATS published CP/CPS v2.7 on 2026-08-19 to add the missing CCADB Policy adherence statement. ATS later explained that the omission came from a task-creation defect in its change-detection process, and it fixed that process on 2026-08-24. ATS also said it verified the updated document, reviewed recent checklist entries for similar omissions, and had no commitments beyond the completed action items. CCADB asked ATS to revise the closure summary to better explain the affected document, root cause, remediation, verification, and any ongoing commitments, and then issued a final call for comments. The bug is now resolved as FIXED, with the incident report closure process having been advanced in the thread.

Model: gpt-5.4-mini Generated: 2026-08-26 10:52 UTC Revised: 2026-09-27 07:01 UTC Confidence: 0.98 7 comments
Chronology
  1. Chrome Root Program Policy v1.8 Section 1.1.3 became effective, requiring explicit CP/CPS adherence language for both the Chrome Root Program Policy and the CCADB Policy.
  2. ATS identified that its CP/CPS lacked the required explicit CCADB Policy adherence statement.
  3. ATS published CP/CPS v2.7 with the missing CCADB Policy adherence language added.
  4. ATS modified its change-detection procedure to require one tracked task per action in a multi-action requirement statement.
  5. ATS reviewed recent checklist entries for other multi-action requirement statements and confirmed no additional omissions.
Thread Activity
  1. Amazon representative — ATS opened a preliminary incident report and said it was self-reporting the CP/CPS gap and would publish a full incident report within 14 days.
  2. Amazon representative — ATS said it had published CP/CPS v2.7 and was preparing the final report within the stated timeframe.
  3. Amazon Trust Services — ATS filed the full incident report, described the root cause as a task-creation defect, said the task creation process was fixed, and requested closure.
  4. CCADB representative — CCADB said the closure summary still needed a clearer explanation of what failed, why it failed, what changed, and any ongoing commitments.
  5. Amazon Trust Services — ATS posted a revised closure summary describing the affected CP/CPS versions, the root cause, the remediation steps, verification, and that there were no commitments beyond the completed action items.
  6. CCADB representative — CCADB issued a final call for comments or questions and said the incident would be closed around 2026-09-21 if there were no further issues.
Participants
Amazon representative Amazon Trust Services CCADB representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#2068900 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Policy Document Issue Opened 2026-09-03 Still Open · 83% similar
Firmaprofesional: CP/CPS missing Chrome Root Program and CCADB policy attestation
#2056668 RESOLVED Self Reported Incident Policy Document Issue Incident Opened By Ca Opened 2026-07-21 · Closed 2026-09-20 · 80% similar
HARICA: Issuance of Server TLS Certificates without AIA OCSP URI against CP/CPS
#2057520 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-07-24 · Closed 2026-09-14 · 80% similar
eMudhra emSign PKI Services: Invalid Subject Locality/State Values
#2052399 RESOLVED Incident Self Reported Incident Repository Issue Remediation Tracking Opened 2026-07-03 · Closed 2026-08-08 · 80% similar
Certainly: Expired certificates on "Valid" and "Revoked" test websites
#2048370 RESOLVED Self Reported Incident Delayed Revocation Remediation Tracking Opened By Ca Opened 2026-06-17 · Closed 2026-08-08 · 80% similar
Sectigo: Delay in some OCSP response signing due to application restart loop
#2033000 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Policy Document Issue Opened 2026-04-17 · Closed 2026-07-09 · 80% similar
SwissSign: Certificate Profile error for S/MIME MV
#2025913 RESOLVED Self Reported Incident Incident Opened 2026-03-24 · Closed 2026-05-18 · 80% similar
IdenTrust: Full Incident Report for Bug 2014609 was not published within 14 days of discovering the issue
#2007116 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Ccadb Disclosure Issue Opened 2025-12-19 · Closed 2026-09-03 · 80% similar
D-Trust: CRL URL Disclosure

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

⚠

Confirm action