Eddy, 

As I noted in my prior correspondence, Comodo has undertaken an internal
review of the Certstar reseller account.  We have informed CertStar that
their email violates their contractual obligation to refrain from sending
unsolicited emails and that their email could be interpreted as misleading
and confusing to the customer.  During our review, we discovered that
Certstar had apparently issued a certificate to mozilla.com without
validating control of the domain.  We immediately revoked the certificate
(prior to your posting) and have suspended Certstar's reseller activities
until our investigation has been completed.  Please let me know if you have
any further problems.  

Regards
Robin Alden
Comodo

> -----Original Message-----
> From: dev-tech-crypto-bounces+robin=comodo....@lists.mozilla.org
> [mailto:dev-tech-crypto-bounces+robin=comodo....@lists.mozilla.org] On
> Behalf Of Eddy Nigg
> Sent: Tuesday, December 23, 2008 1:34 AM
> To: dev-tech-crypto@lists.mozilla.org
> Subject: Re: Unbelievable!
> 
> On 12/23/2008 03:15 AM, Robin Alden:
> > Eddy,
> >     That reseller's ability to sell Comodo certificates has been
> > suspended while we investigate why they are apparently not fulfilling
> their
> > contractual obligations to us.
> 
> How can you outsource such a critical part as domain control validation
> to a reseller is a complete mystery to me! Your controls (if any) have
> completly failed.
> 
> And apparently if the fish stinks at the tail, chances that the head is
> rotten too are pretty high.
> 
> >     We revoked your certificate for mozilla.com.
> >
> 
> I suggest to revoke ALL certificates from this reseller and perform an
> urgent review of your policies and implementations in relation to
> resellers at all. Other steps might be needed as well, you know better
> than me.
> 
> 
> --
> Regards
> 
> Signer: Eddy Nigg, StartCom Ltd.
> Jabber: start...@startcom.org
> Blog:         https://blog.startcom.org
> _______________________________________________
> dev-tech-crypto mailing list
> dev-tech-crypto@lists.mozilla.org
> https://lists.mozilla.org/listinfo/dev-tech-crypto

_______________________________________________
dev-tech-crypto mailing list
dev-tech-crypto@lists.mozilla.org
https://lists.mozilla.org/listinfo/dev-tech-crypto

Reply via email to