EmailSharePrint

Symantec NetSure Protection Plan Version 7.0 June 2011

THIS EXTENDED WARRANTY PROTECTION PLAN ("Plan"), provided by Symantec Corporation and its wholly-owned subsidiaries including, but not limited to GeoTrust, Inc. and thawte, Inc. (collectively, "Symantec"), grants the "NetSure Subscribers" identified in Section 1 limited warranty protection, subject to certain exceptions, disclaimers of warranty, exclusions, and limitations of liability. This Plan is made an integral part of, and is incorporated by reference in, the Service Agreements under which Symantec issues certain digital certificates. See Appendix A for glossary of definitions used in this Plan. A list of Service Agreements appears in Appendix B of this Plan. Appendix C lists the Warranty Limits.

1. Who is Covered. The Plan covers "NetSure Subscribers" holding an eligible "NetSure Certificate". A NetSure Subscriber is a person or entity that is the subject of and has been issued a NetSure Certificate, and is capable of using and is authorized to use the private key that corresponds to the public key listed in the certificate at issue. A listing of the types of digital certificates that are included as being "NetSure Certificates" and therefore subject to this Plan appear in Appendix C. For clarification, certificates that are not covered under the Plan include, but are not limited to: (a) co-branded certificates; (b) white-labeled certificates; and (c) certificates where Symantec does not act as both the "Registration Authority" and the "Certification Authority" for such certificates (as defined in the Symantec Trust Network Certification Practices Statement); for example, certificates validated and processed by Symantec Japan K.K. or any Symantec International Affiliate (http://www.verisign.com/verisign-worldwide/) do not qualify as NetSure Certificates.

2. When the Coverage Applies. Each NetSure Subscriber has a time period in which protection is afforded under the Plan. This period coincides with the span of time in which the NetSure Subscriber's NetSure Certificate is paid for ("Subscription Period").

3. What is Covered.

3.1 Limited Warranty Regarding a NetSure Certificate. Symantec warrants that at the time of issuance of a NetSure Certificate:

(a) there are no material misrepresentations of fact in such NetSure Certificate known to Symantec or originating from Symantec;
(b) there are no errors in the data contained within such NetSure Certificate that were introduced by Symantec as a result of its failure to exercise reasonable care in creating the NetSure Certificate;
(c) the NetSure Certificate met all material requirements of the Service Agreement under which the NetSure Certificate was issued; and
(d) all information in or incorporated by reference in the NetSure Certificate (except information not verified by Symantec) is accurate.

THE WARRANTY IN SECTION 3.1 SHALL NOT APPLY TO THE EXTENT THE BREACH ARISES FROM THE CONDUCT OF THE NETSURE SUBSCRIBER ITSELF (AS OPPOSED TO SYMANTEC) IN ISSUING OR INCORPORATING INFORMATION IN THE NETSURE CERTIFICATE.

3.2 Limited Warranty Against Unauthorized Use, Unauthorized Disclosure, and Compromise. Symantec warrants that, during the Subscription Period, Symantec's private key corresponding to the public key in the NetSure Certificate will not be subject to Compromise, unauthorized use, or unauthorized disclosure negligently caused by or permitted by Symantec prior to the revocation or expiration of such certificate. "Compromise" means a loss, theft, modification, or unauthorized access of a private key corresponding to the public key listed in a NetSure Certificate by cryptographic analysis, key extraction, or any other means.

3.3 Limited Warranties Against Erroneous Issuance. Symantec warrants that, during the Subscription Period, NetSure Certificates are issued to the entities named as subjects of such certificates and were not issued as a result of Erroneous Issuance. "Erroneous Issuance" means issuance of a NetSure Certificate by Symantec in a manner not materially in accordance with the procedures required by the Service Agreement, issuance of a NetSure Certificate by Symantec to an entity other than the one named as the subject of the certificate, or issuance of a NetSure certificate without the authorization of the entity named as the subject of such certificate. THE WARRANTY IN THIS SECTION 3.3 SHALL NOT APPLY TO THE EXTENT THE BREACH ARISES FROM THE CONDUCT OF THE NETSURE SUBSCRIBER ITSELF (AS OPPOSED TO SYMANTEC) IN CAUSING AN ERRONEOUS ISSUANCE.

4. Payments and Payment Requests Under the Plan.

4.1 NetSure Payments. Subject to the limitations in Sections 5, Symantec shall pay a NetSure Subscriber for damages caused by a breach of one or more of the limited warranties in Section 3.

4.2 Requirements for Making a Payment Request. As a condition to payment under Section 4.1, a NetSure Subscriber must:

(a) make a payment request by submitting to Symantec a written report containing the following information: requestor's name, address, phone number and email address; certificate serial number; certificate type; certificate effective date; date of loss; and brief description of the incident (collectively, the "Loss Report"). The Loss Report may be submitted to Symantec either by mail or email. If by mail, to: Symantec Corporation, Attn: Authentication Services Business - NetSure Payment Request, 350 Ellis Street, Mountain View, CA 94043. If by email to: support@symantec.com;
(b) provide other information reasonably requested by Symantec, its agents, or its employees (including without limitation proof of the NetSure Subscriber's damages); and
(c) provide reasonable cooperation with any investigation concerning damages to the NetSure Subscriber.

4.3 Notice and Limitations Period. Symantec shall have no obligation to make a payment under Section 4.1 unless the NetSure Subscriber: (a) submits a Loss Report as required by Section 4.2; and (b) submits such report within one (1) year following the earlier of: (y) the event giving rise to the breach of warranty; or (z) the end of the Subscription Period of the affected NetSure Certificate.

5. Limitations on Payments Under the Plan.

5.1 Limitation on Payments to NetSure Subscribers. The most that Symantec must pay a NetSure Subscriber under the Plan is the "Warranty Limit" that applies under Section 5.2.

5.2 Warranty Limit. The Warranty Limit is determined based on the type of certificate(s) issued to the NetSure Subscriber during the Subscription Period. The Warranty Limit for each type of NetSure Certificate appears in Appendix C, which is incorporated by reference in this Plan. If the NetSure Subscriber holds different types of NetSure Certificates affording different Warranty Limits, then the Warranty Limit of the highest value shall be applicable to that NetSure Subscriber. Warranty Limits are not cumulative.

(a) How the Warranty Limit Works. The Warranty Limit is the most that Symantec shall be obligated to pay a NetSure Subscriber for any and all breaches of Section 3 limited warranties affecting the NetSure Subscriber's NetSure Certificates. All payments under Section 4.1 reduce the amount of the Warranty Limit available for future payments. Once the Warranty Limit of a NetSure Subscriber is exhausted by payments under Section 4.1, Symantec has no further obligation to make further payments under Section 4.1 for breaches relating to that NetSure Subscriber's NetSure Certificate(s).

(b) Erroneous Issuance. One kind of breach of Section 3 is Erroneous Issuance resulting in the issuance of a NetSure Certificate incorrectly naming a NetSure Subscriber. Note: The certificate issued because of Erroneous Issuance is not the same as the NetSure Subscriber's own (correctly-issued) certificate. When this kind of breach occurs, only one Warranty Limit applies to the breach. Any payments made under Section 4.1 reduce the applicable Warranty Limit. Further, the issuance of a certificate as a result of Erroneous Issuance is a single breach regardless of: (i) how many parties rely on that certificate; (ii) the number or amount of losses sustained by the NetSure Subscriber as a result of the issuance of such certificate; or (iii) the number of other certificates held by the NetSure Subscriber.

6. Refund Policy. If Symantec breaches a limited warranty made to a NetSure Subscriber under Section 3 or a material obligation under the applicable Service Agreement, then Symantec shall, at the NetSure Subscriber's request, revoke the NetSure Subscriber's certificate and provide the NetSure Subscriber with a refund of the amount paid by the NetSure Subscriber for the certificate. To request a refund, NetSure Subscribers must adhere to the refund policy published at https://www.verisign.com/repository/refund. This refund policy is not an exclusive remedy and does not limit other remedies that may be available to NetSure Subscribers.

7. PERSONS EXCLUDED FROM THE PLAN. SYMANTEC PROVIDES THE LIMITED WARRANTIES IN SECTION 3 ONLY TO THE NETSURE SUBSCRIBERS IDENTIFIED IN SECTION 1. SYMANTEC MAKES NO WARRANTY UNDER THIS PLAN TO ANY OTHER PERSON. THIS PLAN IS NOT INTENDED TO CREATE ANY THIRD PARTY BENEFICIARY RIGHTS FOR ANY OTHER PERSON.

8. Liability Caused by Party Other Than Symantec. The limited warranties in Section 3 do not apply to losses or damages caused in whole or in part by a third party or a certificate subscriber's own breach of any warranty or obligation in its Service Agreement. Symantec shall not be liable for actions outside its scope of control. In connection therewith, Symantec shall not be liable for any loss or damage that is not due to a defect in materials or workmanship of a Symantec digital certificate or otherwise caused by Symantec's negligence or breach of its contractual obligations under the Service Agreement. In no event shall Symantec be liable for any loss or damage that results from any fortuitous event(s).

9. Exceptions to the Plan. The limited warranties in Section 3 do not apply to losses or damages of a NetSure Subscriber, caused wholly or partially by:

(a) breach by such NetSure Subscriber of a material obligation under the Service Agreement;
(b) Use of certificates in a manner outside the permitted scope of use as set forth in the applicable Service Agreement;
(c) Reliance upon information contained in or incorporated in a NetSure Certificate, whether or not published in the Symantec repository, where such reliance is unreasonable or unjustified for any reason, in light of, among other things, facts that the NetSure Subscriber knows or should know, the course of dealing between pertinent parties or trade usage;
(d) The failure or unreasonable delay of such NetSure Subscriber to properly communicate a request for revocation of a NetSure Certificate as required by the Service Agreement;
(e) The failure of such NetSure Subscriber to exercise reasonable care to prevent Compromise of the NetSure Subscriber's own private key including, but not limited to, failure of such NetSure Subscriber to use a trustworthy system to protect its private key;
(f) The failure of a NetSure Subscriber to apply reasonable security measures to verify the digital signature of the NetSure Certificate;
(g) The failure of such NetSure Subscriber to apply reasonable security measures prior to and during the creation, storage, and transfer of encrypted messages, including without limitation (i) the failure to determine that such NetSure Certificate is an operational certificate; and (ii) the failure to validate a certificate chain for the NetSure Certificate;
(h) The failure, if applicable, of such NetSure Subscriber to use a RSA public key algorithm with at least the designated and available modulus size;
(i) The failure, if applicable, of such NetSure Subscriber to use any public key algorithm other than RSA;
(j) Any condition or incident of force majeure under the Service Agreement;
(k) Acts by any persons whose illegal or unauthorized conduct damages, alters, impedes, or otherwise misuses the facilities or services of Internet service providers or other providers of telecommunications or value-added services including, but not limited to, the use or reproduction of malicious software such as computer viruses;
(l) The failure of communications infrastructure, processing, or storage media or mechanisms, including components thereof, not under the exclusive ownership or control of Symantec;
(m) Brown-outs, power failures, or other disturbances to electrical power;
(n) Illegal acts by a person coercing the NetSure Subscriber to perform acts causing the NetSure Subscriber's loss or damages;
(o) Use or reliance upon demo or test certificates; and
(p) Such NetSure Subscriber's monitoring, interfering with, or reverse engineering, directly or indirectly, the technical implementation of the Symantec public certification services.

10. Disclaimers of Warranty.

10.1 SPECIFIC DISCLAIMERS. EXCEPT AS EXPRESSLY STATED IN SECTION 3, SYMANTEC:

(A) DOES NOT WARRANT THAT NONVERIFIED SUBSCRIBER INFORMATION CONTAINED IN NETSURE CERTIFICATES IS ACCURATE, AUTHENTIC, RELIABLE, COMPLETE, CURRENT, MERCHANTABLE, OR FIT FOR A PARTICULAR PURPOSE;
(B) SHALL NOT INCUR LIABILITY FOR REPRESENTATIONS CONTAINED IN A NETSURE CERTIFICATE, PROVIDED THE CERTIFICATE WAS PREPARED SUBSTANTIALLY IN COMPLIANCE WITH THE SERVICE AGREEMENT;
(C) DOES NOT WARRANT "NONREPUDIATION" FOR ANY NETSURE CERTIFICATE OR ANY MESSAGE (BECAUSE NONREPUDIATION IS DETERMINED EXCLUSIVELY BY LAW AND THE APPLICABLE FINAL DISPUTE RESOLUTION MECHANISM); AND
(D) SHALL NOT BE RESPONSIBLE FOR THE PERFORMANCE OF ANY HARDWARE OR SOFTWARE NOT UNDER EXCLUSIVE OWNERSHIP OF, EXCLUSIVE CONTROL OF, OR LICENSED TO SYMANTEC.

10.2 GENERAL DISCLAIMER. EXCEPT AS EXPRESSLY PROVIDED IN SECTION 3 AND THE SERVICE AGREEMENT, AND TO THE EXTENT PERMITTED BY APPLICABLE LAW, SYMANTEC DISCLAIMS: (A) ANY AND ALL OTHER EXPRESS OR IMPLIED WARRANTIES AND OBLIGATIONS OF ANY TYPE, INCLUDING ANY WARRANTY OF MERCHANTABILITY, ANY WARRANTY OF FITNESS FOR A PARTICULAR PURPOSE, AND ANY WARRANTY OF THE ACCURACY OF INFORMATION PROVIDED BY CERTIFICATE APPLICANTS, SUBSCRIBERS, AND THIRD PARTIES; AND (B) ANY LIABILITY FOR ANY ACTS BY THIRD PARTIES THAT CONSTITUTE OR MAY BE HELD TO CONSTITUTE NEGLIGENCE, RECKLESSNESS, AND/OR STRICT LIABILITY, WHETHER SOLELY OR JOINTLY ACTED WITH ANY OTHER PERSON INCLUDING, BUT NOT LIMITED TO, ANY NETSURE SUBSCRIBER.

11. LIMITATION ON DAMAGES. IN THE EVENT A NETSURE SUBSCRIBER INITIATES ANY CLAIM, ACTION, SUIT, ARBITRATION, OR OTHER PROCEEDING SEPARATE FROM A REQUEST FOR PAYMENT UNDER SECTION 4.2, AND TO THE EXTENT PERMITTED BY APPLICABLE LAW, SYMANTEC'S TOTAL LIABILITY FOR DAMAGES SUSTAINED BY ANY AND ALL NETSURE SUBSCRIBERS, COMBINED WITH ANY AND ALL DAMAGES SUSTAINED BY ANY AND ALL OTHER PERSONS CAUSED BY THE USE OF OR RELIANCE ON ANY NETSURE CERTIFICATE SHALL BE LIMITED TO AN AMOUNT NOT TO EXCEED $5,000, FOR THE TOTAL OF ALL DIGITAL SIGNATURES, TRANSACTIONS, AND CLAIMS RELATED TO ANY SUCH NETSURE CERTIFICATE. THE LIABILITY CAP PROVIDED IN THIS SECTION SHALL BE THE SAME REGARDLESS OF THE NUMBER OF DIGITAL SIGNATURES, TRANSACTIONS, OR CLAIMS RELATED THERETO. THIS SECTION DOES NOT LIMIT REFUND PAYMENTS UNDER SECTION 6 OR PAYMENTS UNDER SECTION. SYMANTEC SHALL NOT BE OBLIGATED TO PAY MORE THAN THE WARRANTY LIMIT FOR EACH NETSURE SUBSCRIBER. THIS SECTION APPLIES TO LIABILITY UNDER CONTRACT (INCLUDING BREACH OF WARRANTY), TORT (INCLUDING NEGLIGENCE AND/OR STRICT LIABILITY), AND ANY OTHER LEGAL OR EQUITABLE FORM OF CLAIM.

12. EXCLUSION OF CERTAIN ELEMENTS OF DAMAGES. EXCEPT AS EXPRESSLY PROVIDED IN SECTIONS 4 AND 5, AND TO THE EXTENT PERMITTED BY APPLICABLE LAW, SYMANTEC SHALL NOT BE LIABLE FOR ANY INDIRECT, SPECIAL, RELIANCE, INCIDENTAL, OR CONSEQUENTIAL DAMAGES (INCLUDING BUT NOT LIMITED TO ANY LOSS OF PROFITS OR LOSS OF DATA), ARISING FROM OR IN CONNECTION WITH THE USE, DELIVERY, LICENSE, PERFORMANCE, OR NONPERFORMANCE OF CERTIFICATES, DIGITAL SIGNATURES, OR ANY OTHER TRANSACTIONS OR SERVICES OFFERED OR CONTEMPLATED BY THE SERVICE AGREEMENTS OR THIS PLAN, EVEN IF SYMANTEC HAD BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

13. EXCLUSION OF PUNITIVE DAMAGES. TO THE EXTENT PERMITTED BY APPLICABLE LAW, SYMANTEC SHALL NOT BE LIABLE FOR ANY PUNITIVE DAMAGES ARISING FROM OR IN CONNECTION WITH THE USE, DELIVERY, LICENSE, PERFORMANCE, OR NONPERFORMANCE OF CERTIFICATES, DIGITAL SIGNATURES, OR ANY OTHER TRANSACTIONS OR SERVICES OFFERED OR CONTEMPLATED BY THE SERVICE AGREEMENTS OR THIS PLAN.

14. Severability. In the event that any provision of this Plan should be found by a court of competent jurisdiction to be invalid, illegal or unenforceable in any respect, the validity, legality and enforceability of the remaining provisions contained shall not, in any way, be affected or impaired thereby.

15. Amendments. Symantec shall be entitled to amend this Plan from time to time (prospectively and not retroactively). Any such change will be binding and effective thirty (30) days after publication of the change on Symantec's websites, or upon notification to the NetSure Subscriber by email. If the NetSure Subscriber does not agree with the change, the NetSure Subscriber may notify Symantec, request revocation of its NetSure Certificate(s) and a partial refund of fees paid, prorated from the date of revocation to the end of the Subscription Period(s). By continuing to use the NetSure Certificate(s) after such change, the NetSure Subscriber shall be deemed to have agreed to abide by and by bound by such change.

16. Governing Law. Any disputes related to the services provided under this Plan shall be governed in all respects by and construed in accordance with the laws of the State of California, United States of America, excluding its conflict of laws rules. The parties agree that the United Nations Convention on Contracts for the International Sale of Goods shall not apply.

17. Dispute Resolution. To the extent permitted by law, before any party files suit or initiates an administrative claim with respect to a dispute involving any aspect of this Plan, the parties shall make good faith efforts to resolve such dispute via business discussions. If the dispute is not resolved within sixty (60) days after the initial notice, then a party may proceed as permitted under applicable law as specified under this Plan.

Appendix A: GLOSSARY OF DEFINED TERMS

1. General Definitions. Unless otherwise noted in the Plan, defined terms shall have the meanings given to them in the Certification Practices Statement applicable to the respective certificate.

2. Definitions Specific to the Plan.

(a) Compromise. See Section 3.2

(b) Erroneous Issuance. See Section 3.3

(c) Loss Report. See Section 4.2

(d) NetSure Certificate. See Section 1

(e) NetSure Subscriber. See Section 1

(f) Plan. "Plan" means the NetSure Protection Plan, i.e., this document. For clarification, this document: (i) applies equally to the GeoSure Protection Plan and the Thawte Protection Plan; and (ii) supersedes previous versions of the GeoSure Protection Plan.

(g) Service Agreement. "Service Agreement" means, at any given time, the current version of the agreement(s) under which a NetSure Subscriber obtained a NetSure Certificate. See Appendix B.

(h) Subscription Period. See Section 2

(i) Warranty Limit. See Sections 5.1 and 5.2

Appendix B: LIST OF SERVICE AGREEMENTS

This Plan is made an integral part of, and is incorporated by reference in, the following Service Agreements:

Appendix C: WARRANTY LIMITS

The following certificates are NetSure Certificates:
If Issued On or After:
July 30, 2011
WHERE THE NETSURE SUBSCRIBER HOLDS: THE WARRANTY LIMIT IS:
Symantec Trust Network Certificates
SECURE SITE WITH EXTENDED VALIDATION;
SECURE SITE PRO WITH EXTENDED VALIDATION;
MPKI FOR SSL STANDARD WITH EXTENDED VALIDATION;
MPKI FOR SSL PREMIUM WITH EXTENDED VALIDATION
USD $1,500,000
SECURE SITE PRO CERTIFICATE;
MPKI FOR SSL PREMIUM CERTIFICATE
USD $1,250,000
SECURE SITE CERTIFICATE;
MPKI FOR SSL STANDARD CERTIFICATE
USD $1,000,000
WILDCARD SSL CERTIFICATE USD $500,000
MPKI FOR INTRANET SSL PREMIUM CERTIFICATE USD $250,000
MPKI FOR INTRANET SSL STANDARD CERTIFICATE;
CODE SIGNING CERTIFICATE**
USD $125,000
ANY SYMANTEC TRUST NETWORK CERTIFICATE SUBJECT TO THE LICENSED CERTIFICATE OPTION USD $10,000
**CODE SIGNING CERTIFICATES ISSUED PURSUANT TO CODE SIGNING PORTAL ACCOUNTS ARE NOT CONSIDERED NETSURE CERTIFICATES USD $0
Thawte Certificates
THAWTE SSL WEB SERVER CERTIFICATE WITH EXTENDED VALIDATION USD $750,000
THAWTE SGC SUPERCERT USD $500,000
THAWTE SSL WEB SERVER CERTIFICATE USD $250,000
THAWTE WILDCARD SSL CERTIFICATE USD $125,000
THAWTE SSL123 CERTIFICATE USD $100,000
THAWTE CODE SIGNING CERTIFICATE USD $50,000
Geotrust Certificates
GEOTRUST TRUE BUSINESSID WITH EXTENDED VALIDATION USD $500,000
GEOTRUST TRUE BUSINESSID;
GEOTRUST ENTERPRISE SSL STANDARD CERTIFICATE;
GEOTRUST ENTERPRISE SSL PREMIUM CERTIFICATE
USD $250,000
GEOTRUST TRUE BUSINESSID WILDCARD;
GEOTRUST ENTERPRISE SSL WILDCARD CERTIFICATE
USD $125,000
GEOTRUST QUICK SSL PREMIUM CERTIFICATE USD $100,000
CERTIFICATES ISSUED PURSUANT TO GEOROOT ACCOUNTS ARE NOT CONSIDERED NETSURE CERTIFICATES USD $0
RapidSSL Certificates
RAPIDSSL CERTIFICATE USD $10,000
RAPIDSSL ENTEPRISE CERTIFICATE USD $10,000
RAPIDSSL WILDCARD SSL CERTIFICATE USD $5,000