← HARICA cases
Bugzilla #1530971 Policy Compliance

HARICA: P-384,ecdsa-with-SHA256 Certificates

RESOLVED FIXED HARICA
AI Summary

HARICA identified a compliance issue where it had issued Intermediate CA Certificates using ECDSA P-384 keys with SHA256 hashing, violating Mozilla's Root Store Policy. This was discovered during a policy review on February 25, 2019. Following the identification, HARICA disabled certificate issuance from the affected subCAs and conducted a database scan, revealing one affected end-entity certificate and five intermediate CA certificates. The problematic certificates were planned for revocation by March 8, 2019, and mitigation measures were implemented to prevent recurrence. The issue has since been resolved.

Model: gpt-4o-mini Generated: 2026-06-13 18:03 UTC Confidence: 0.95
Chronology
  1. Compliance issue discovered during policy review.
  2. Planned revocation of affected certificates.
  3. Feature request created for CA software to prevent similar issues.
  4. Remediation confirmed complete.
Participants
Dimitris Zacharopoulos W. Thayer
Similar Local Cases
#1567061 RESOLVED Policy Compliance Opened 2019-07-18 · Closed 2023-02-22 · 47% similar
GoDaddy: inconsistent disclosure of externally-operated intermediate
#1542082 RESOLVED Policy Compliance Opened 2019-04-04 · Closed 2023-02-22 · 43% similar
IdenTrust: Failure to disclose Unconstrained intermediate Within 7 Days
#1519265 RESOLVED Policy Compliance Opened 2019-01-10 · Closed 2025-08-18 · 42% similar
QuoVadis: Recap of BR Compliance in 2018 issuance by external subCAs
#1518560 RESOLVED Policy Compliance Opened 2019-01-08 · Closed 2023-02-22 · 42% similar
Asseco DS / Certum: Use of forbidden subjectPublicKeyInfo algorithm
#1391066 RESOLVED Policy Compliance Opened 2017-08-16 · Closed 2023-02-22 · 41% similar
SwissSign: Non-BR-Compliant Certificate Issuance
#1391864 RESOLVED Policy Compliance Opened 2017-08-19 · Closed 2023-02-22 · 41% similar
Staat der Nederlandend / PKIoverheid: Non-BR-Compliant Certificate Issuance
#586414 RESOLVED Policy Compliance Opened 2010-08-11 · Closed 2022-11-14 · 41% similar
Verify GlobalSign's continued conformance to EV guidelines
#1970565 RESOLVED Policy Compliance Opened 2025-06-05 · Closed 2025-07-08 · 41% similar
ANF AC: Finding #2 ETSI Audit - Information security policy not updated on the website

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action