Closed Bug 2015566 Opened 7 months ago Closed 3 months ago

Echoworx: Missing Contact Information in CCADB

Categories

(CA Program :: CA Certificate Compliance, task)

Tracking

(Not tracked)

RESOLVED WONTFIX

People

(Reporter: dhollenback, Assigned: ew-contact)

Details

(Whiteboard: [ca-compliance] [disclosure-failure])

Issue

Echoworx has not updated required CCADB contact information after being notified on 2026‑01‑23, and no update has been submitted as of now.

The required fields “CA Email Alias 1” and “CA Email Alias 2” are empty.

This violates CCADB Policy Section 2 – Contact Information Disclosures, which states:

“CA Owners MUST also supply at least one non-personal contact email alias that is more likely to continue working as personnel change; these are maintained as part of the CA’s organizational entry.”

Requested Action

Echoworx must populate at least one of the required alias fields (“CA Email Alias 1” or “CA Email Alias 2”) by submitting an “Add/Update Root Request” case, and ensure future updates are made within the policy‑mandated 14‑day timeframe.

Assignee: nobody → ew-contact
Status: UNCONFIRMED → ASSIGNED
Ever confirmed: true
Whiteboard: [ca-compliance] [disclosure-failure]

Case has been opened. 00002957

Based on the facts described above, Echoworx is required to complete the incident reporting process set forth in the CCADB Incident Reporting Guidelines.

Flags: needinfo?(ew-contact)

Hello Ben,

Echoworx is no longer being WebTrust audited, and is no longer a CA. Echoworx can be removed from the program. We have advised this several times via email.

Please advise if further action is required.

Thank you.

Flags: needinfo?(ew-contact)

Thanks for the reminder/clarification. As I understand, the Echoworx Root CA2 remains in the Microsoft Root Store and according to CCADB records, it has a distrust notbefore date of 15 September 2025, such that:

  • Certificates issued after 15 September 2025 under Echoworx Root CA2 are distrusted by Microsoft, and
  • Certificates issued before that date and chaining to Echoworx Root CA2 may continue to be trusted, subject to their validity period and revocation checks.

So, I assume that Echoworx might still have some active/valid certificates (smime, doc-signing, clientAuth) that were issued under the Echoworx Root CA2 hierarchy prior to 15 September 2025.

Thanks,

Please advise what further actions are required from us.

Status: ASSIGNED → RESOLVED
Closed: 3 months ago
Resolution: --- → WONTFIX
You need to log in before you can comment on or make changes to this bug.