View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
0001580 | Main CAcert Website | account administration | public | 2025-05-05 14:43 | 2025-05-05 14:43 |
Reporter | alkas | Assigned To | |||
Priority | high | Severity | major | Reproducibility | always |
Status | new | Resolution | open | ||
Platform | Default | OS | any | OS Version | any |
Product Version | 2017 Q4 | ||||
Target Version | 2017 Q4 | ||||
Summary | 0001580: Add a sentence to the standard "Delete account init" Email text | ||||
Description | It is almost sure now, that revoking certificates by the user extends the account deletion possibility by 90 days from the date when certificates were revoked. I propose to add a sentence to the standard text. The sentence: ---- PLEASE DO NOT REVOKE THEM YOURSELF !! (This will extend the deletion process by 90 days.) ---- and the whole text should be: ---- Hello X Y, we received a request to delete your CAcert account dated 2025-04-25 04:08:06. Please read this mail carefully, as some further activity from you may be required. !!! Please confirm or reject the account deletion by answering to this mail !!! For further communication please use the ticket number s20250425.96 as reference in the subject of your answers. IF YOU DO NOT WANT YOUR CACERT ACCOUNT CLOSED, PLEASE CONTACT US AS SOON AS POSSIBLE! If you do not respond within 14 days we will initiate the closure of your account as requested. You can fasten this process by confirming your wish to get your account closed. If you lost your password and/or secret answers for your questions, please contact us, so we can start the lost-password-process. Be aware that some risks, liabilities and obligations for the time of your membership, may continue even when the membership has ended. Regarding your certificates: There may be valid certificates in your account. As soon as we start with the delete account process, all these certificates will be revoked, if you do not state otherwise. PLEASE DO NOT REVOKE THEM YOURSELF !! (This will extend the deletion process by 90 days.) We are required to keep accounts open for 3 months after the last certificate is expired or revoked. How we close your account: We have to keep some references to the accounts, for example to be able to report about our issued certificates, so we cannot delete all data. We will do the following to close your account: - your personal data (name, date of birth) will be set to some defaults - your email addresses will be removed and an address referencing this support case will be added - any access to your account will be blocked and the password set to a random string - all flags will be reset After this is done, we will be able to release you out of the CAcert Community Agreement (CCA) and by this you will finally stop to be a member of CAcert. Until then all risks, obligation and liabilities will continue. https://www.cacert.org/policy/CAcertCommunityAgreement.html Possibility to block your account for further access As you probably do not have an interest to access your account any more, we can set a lock on your account, so nobody can access it any longer, when we initiate the closure of your account. This would free you from the need to take care by yourself, that nobody else accesses your account. If you do want or do not want this, please say so. You can change your mind on above decisions later, as long as your account is open. If the account is deleted, the only way to (re)join the CAcert community again is to create a new account (and get assured again). | ||||
Steps To Reproduce | SE cannot delete an account, if the user: - has at least one issued certificate, no matter if already expired or revoked, - revoke his/her cerificates him/herself, despite the previous fact(s). | ||||
Additional Information | The result: the described behaviour makes the communication with some kind of users very unpleasant. | ||||
Tags | delete user accounts | ||||
Reviewed by | |||||
Test Instructions | see steps above | ||||