← Amazon Trust Services cases
Bugzilla #1743935
Certificate Misissuance
Amazon Trust Services: Misissuance of Subordinate Per CPS
RESOLVED
FIXED
Amazon Trust Services
AI Summary
Amazon Trust Services reported a misissuance of a subordinate certificate that violated their Certificate Policy Statement (CPS). The issue was identified on November 25, 2021, leading to an investigation that confirmed the certificate's issuance was in violation of the CPS. The CA took corrective actions, including revocation of the problematic certificates on December 8, 2021. The incident was resolved with no impact to relying parties as the affected certificates were not in use.
Chronology
- Amazon Trust Services received a report regarding the misissued certificate.
- Certificates identified as problematic were revoked.
- Incident closure confirmed.
Participants
Trevoli (Amazon Trust Services)
Corey Bonnell (DigiCert)
Ryan Sleevi
External References
Similar Local Cases
Amazon Trust Services: No Space In Private Organization
Amazon Trust Services: CAA Misissuances
Amazon Trust Services: Certificates issued for "testing.com"
DigiCert: Validation Scope Incident
DigiCert: Domain validation skipped
ACCV: Insufficient serial number entropy
E-Tugra: Improper DER results in failure to comply with RFC 5280 - Invalid characters in PrintableString
SwissSign: Invalid DNSName in SAN