← Amazon Trust Services cases
Bugzilla #1746945
Technical Compliance
Amazon Trust Services: Missing CAA Check For Test Website Certificates
RESOLVED
FIXED
Amazon Trust Services
AI Summary
Amazon Trust Services identified a failure to perform CAA checks for certificates issued for test websites during an internal audit on December 8, 2021. This oversight affected ten certificates, five of which were revoked shortly after issuance. The team recognized the need for CAA checks and halted further certificate issuance until the issue was resolved. The incident highlights the importance of compliance with technical requirements in certificate management.
Chronology
- Internal audit reveals missing CAA check for test certificates.
- Five test certificates revoked due to missed CAA check.
Participants
Trevoli (Amazon Trust Services)
Matthias
Ben Wilson (Mozilla)
External References
Similar Local Cases
Amazon Trust Services: CRL not DER-encoded
Amazon Trust Services: Failure to comply with RFC 5280
Entrust: Non-BR-Compliant OCSP Responder
Apple: CRL issuance frequency deviates from CPS in some cases
Consorci AOC: Non-BR-Compliant OCSP Responders
Firmaprofesional: Non-BR-Compliant OCSP Responders
DigiCert: SCEE / Justica: Non-BR-Compliant Certificate Issuance
Visa: Non-BR-Compliant OCSP Responders