← certSIGN cases
Bugzilla #1390979
Policy Compliance
certSIGN: Non-BR-Compliant Certificate Issuance
RESOLVED
FIXED
certSIGN
AI Summary
certSIGN faced issues with the issuance of non-Baseline Requirements (BR) compliant certificates, including invalid common names and SAN entries. The CA acknowledged the problems and confirmed that they ceased issuing non-compliant certificates. They provided a detailed remediation plan, including the implementation of technical controls to ensure compliance with BRs. Regular updates and communication with auditors were established to monitor progress. The case has been resolved with all planned remediations successfully implemented.
Chronology
- Initial report of non-compliance issued.
- certSIGN acknowledged issues and began remediation.
- Dedicated email for problem reporting created.
- Technical controls for BR compliance implemented.
- All planned remediations completed, case closed.
Participants
Kathleen Wilson
Cristian Garabet
Vincent Lynch
Ryan Sleevi
External References
Similar Local Cases
Izenpe: Non-BR-Compliant Certificate Issuance
GoDaddy: Non-BR-Compliant Certificate Issuance
Entrust: Non-BR-Compliant Certificate Issuance
SECOM: Non-BR-Compliant Certificate Issuance
SwissSign: Non-BR-Compliant Certificate Issuance
QuoVadis: Non-BR-Compliant Certificate Issuance
Kamu SM: Non-BR-Compliant Certificate Issuance
Actalis: Non-BR-Compliant Certificate Issuance