Eddy, As I noted in my prior correspondence, Comodo has undertaken an internal review of the Certstar reseller account. We have informed CertStar that their email violates their contractual obligation to refrain from sending unsolicited emails and that their email could be interpreted as misleading and confusing to the customer. During our review, we discovered that Certstar had apparently issued a certificate to mozilla.com without validating control of the domain. We immediately revoked the certificate (prior to your posting) and have suspended Certstar's reseller activities until our investigation has been completed. Please let me know if you have any further problems.
Regards Robin Alden Comodo > -----Original Message----- > From: dev-tech-crypto-bounces+robin=comodo....@lists.mozilla.org > [mailto:dev-tech-crypto-bounces+robin=comodo....@lists.mozilla.org] On > Behalf Of Eddy Nigg > Sent: Tuesday, December 23, 2008 1:34 AM > To: dev-tech-crypto@lists.mozilla.org > Subject: Re: Unbelievable! > > On 12/23/2008 03:15 AM, Robin Alden: > > Eddy, > > That reseller's ability to sell Comodo certificates has been > > suspended while we investigate why they are apparently not fulfilling > their > > contractual obligations to us. > > How can you outsource such a critical part as domain control validation > to a reseller is a complete mystery to me! Your controls (if any) have > completly failed. > > And apparently if the fish stinks at the tail, chances that the head is > rotten too are pretty high. > > > We revoked your certificate for mozilla.com. > > > > I suggest to revoke ALL certificates from this reseller and perform an > urgent review of your policies and implementations in relation to > resellers at all. Other steps might be needed as well, you know better > than me. > > > -- > Regards > > Signer: Eddy Nigg, StartCom Ltd. > Jabber: start...@startcom.org > Blog: https://blog.startcom.org > _______________________________________________ > dev-tech-crypto mailing list > dev-tech-crypto@lists.mozilla.org > https://lists.mozilla.org/listinfo/dev-tech-crypto _______________________________________________ dev-tech-crypto mailing list dev-tech-crypto@lists.mozilla.org https://lists.mozilla.org/listinfo/dev-tech-crypto