← Amazon Trust Services cases
Bugzilla #1713978
Policy Compliance
Amazon Trust Services: Forbidden Domain Validation Method 3.2.2.4.6
RESOLVED
FIXED
Amazon Trust Services
AI Summary
The case involves Amazon Trust Services' use of a domain validation method (3.2.2.4.6) that is prohibited by the Baseline Requirements. Concerns were raised regarding the clarity and compliance of their Certification Practice Statement (CPS) and Certification Policy (CP). Amazon acknowledged the feedback and committed to updating their documents to ensure compliance. By July 30, 2021, they planned to clarify their practices regarding validation methods. The issue was resolved when updated CP and CPS documents were published on July 23, 2021.
Chronology
- Initial report of the forbidden domain validation method.
- Amazon committed to updating their CP and CPS.
- Amazon published updated CP and CPS documents.
Participants
Andrew Ayer
Trevoli (Amazon Trust Services)
Ryan Sleevi
External References
Similar Local Cases
Amazon Trust Services: CP/CPS does not specify key compromise methods
Amazon Trust Services - BR Self Assessment and CP/CPS Updates
EDICOM: Signing SHA-1 OCSP responses with unconstrained certificate
Sectigo: Missing Changelog in CPS
DigiCert: Verizon CPS lacks CPR problem reporting instructions
SwissSign: BRs require full annual audits
Ernst & Young Poland: KIR OCSP "unknown" status for revoked certificate
SECOM: Non-BR-Compliant Certificate Issuance