← HARICA cases
Bugzilla #1530971 Ca Certificate Compliance Self Reported Incident

HARICA: P-384,ecdsa-with-SHA256 Certificates

RESOLVED FIXED HARICA
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

HARICA disclosed an incident it discovered during a detailed policy documents review in February 2019. HARICA found that it had issued intermediate CA certificates using the ECDSA P-384 key with the SHA256 hashing algorithm, which it stated violates Section 5.1 of the Mozilla Root Store Policy (effective February 28, 2017). HARICA explained that its CA software (EJBCA) was configured to inherit the Root CA key/hash combination and used the SHA256ECDSA algorithm while the key was P-384, resulting in subCA and end-entity certificates with the same pair (SHA256, P-384). After verifying the finding and creating an internal incident, HARICA disabled certificate issuance from the affected subCAs and performed a database scan, which it said found one affected end-entity certificate for a test web site and five affected intermediate CA certificates. HARICA reported that the affected CA certificates were revoked and marked accordingly in CCADB, and that remediation was complete. HARICA also stated it created a feature request with its CA software manufacturer (PrimeKey) to add validators for this rule and enforced its P-384 subCAs to use SHA384 when signing end-entity certificates, and it opened a GitHub issue with recommended language to clarify the requirement.

Model: gpt-5.4-nano Generated: 2026-06-13 18:03 UTC Revised: 2026-06-16 19:09 UTC Confidence: 0.90 6 comments
Chronology
  1. HARICA discovered during a policy document review that it had issued intermediate CA certificates with an ECDSA P-384 key using SHA256 hashing, contrary to Mozilla Root Store Policy.
  2. HARICA disabled certificate issuance from affected subCAs and reported the incident to Mozilla, including results of a database scan and planned revocation timeline.
  3. HARICA revoked the affected CA certificates and marked them accordingly in CCADB (as stated in the final report).
Thread Activity
  1. HARICA — Created the initial incident report, stating HARICA discovered the P-384/SHA256 issuance issue, disabled issuance from affected subCAs, scanned the database, and planned revocation by March 8, 2019.
  2. HARICA — Submitted a final report after revoking the affected CA certificates and marking them in CCADB.
  3. Fastly representative — Asked about the status of an action item to request additional validators from the CA software manufacturer.
  4. HARICA — Said a ticket was created for PrimeKey to check the rule, noted HARICA enforced P-384 subCAs to use SHA384 for end-entity signing, and referenced a GitHub issue to clarify the requirement.
  5. Fastly representative — Commented that it appears remediation is complete.
  6. HARICA — Provided a link for the community to follow progress on the PrimeKey feature request.
Participants
HARICA Fastly representative
Similar Local Cases
#1872374 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2023-12-29 · Closed 2026-06-10 · 89% similar
HARICA: subject:organizationIdentifier using VATEL as a prefix for tax identifier
#1699796 RESOLVED Self Reported Incident Certificate Misissuance Opened 2021-03-19 · Closed 2023-02-22 · 88% similar
HARICA: Certificates with invalid policy tree
#1649945 RESOLVED Self Reported Incident Opened 2020-07-02 · Closed 2023-02-22 · 87% similar
HARICA: Incorrect OCSP Delegated Responder Certificate
#1580393 RESOLVED Incident Self Reported Incident Opened 2019-09-11 · Closed 2022-11-14 · 81% similar
HARICA: OCSP Responder Returned "Unauthorized" for Some Precertificates
#2029643 RESOLVED Self Reported Incident Revocation Issue Certificate Misissuance Opened 2026-04-06 · Closed 2026-05-22 · 80% similar
HARICA: Incorrect Open MPIC Lambda implementation by EJBCA ACME Service
#1538638 RESOLVED Ca Certificate Compliance Self Reported Incident Revocation Issue Opened 2019-03-25 · Closed 2023-02-22 · 79% similar
Firmaprofesional: AC Firmaprofesional - INFRAESTRUCTURA insufficient serial number entropy
#1579950 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-09-09 · Closed 2022-11-14 · 78% similar
QuoVadis: OCSP handling of Certificate Transparency Pre-certs
#2017845 RESOLVED Certificate Misissuance Self Reported Incident Problem Reporting Failure Opened 2026-02-19 · Closed 2026-06-29 · 78% similar
HARICA: Incorrect nCAId in PSD2 QCStatement for QWACs

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action