← HARICA cases
Bugzilla #1530971 Policy Compliance

HARICA: P-384,ecdsa-with-SHA256 Certificates

RESOLVED FIXED HARICA
AI Summary

HARICA identified a compliance issue where it had issued Intermediate CA Certificates using ECDSA P-384 keys with SHA256 hashing, violating Mozilla's Root Store Policy. This was discovered during a policy review on February 25, 2019. Following the identification, HARICA disabled certificate issuance from the affected subCAs and conducted a database scan, revealing one affected end-entity certificate and five intermediate CA certificates. The problematic certificates were planned for revocation by March 8, 2019, and mitigation measures were implemented to prevent recurrence. The issue has since been resolved.

Model: gpt-4o-mini Generated: 2026-06-13 18:03 UTC Confidence: 0.95
Chronology
  1. Compliance issue discovered during policy review.
  2. Planned revocation of affected certificates.
  3. Feature request created for CA software to prevent similar issues.
  4. Remediation confirmed complete.
Participants
Dimitris Zacharopoulos W. Thayer
Similar Local Cases
#1567061 RESOLVED Policy Compliance Opened 2019-07-18 · Closed 2023-02-22 · 47% similar
GoDaddy: inconsistent disclosure of externally-operated intermediate
#1850807 RESOLVED Policy Compliance Opened 2023-08-30 · Closed 2023-09-29 · 43% similar
IdenTrust: basicConstraints not flagged "Critical" Per Certification Practices Statement
#1959721 RESOLVED Policy Compliance Opened 2025-04-10 · Closed 2025-06-12 · 43% similar
Lawtrust: The S/MIME CA’s policy identifiers did not align with the CA/Browser Forum Requirements.
#1542082 RESOLVED Policy Compliance Opened 2019-04-04 · Closed 2023-02-22 · 43% similar
IdenTrust: Failure to disclose Unconstrained intermediate Within 7 Days
#1935393 RESOLVED Policy Compliance Opened 2024-12-05 · Closed 2025-01-29 · 42% similar
Asseco DS / Certum: Failure to Update Policy Documents within 365 Days
#1658995 RESOLVED Policy Compliance Opened 2020-08-13 · Closed 2024-05-09 · 42% similar
Microsoft PKI Services: Firewall log data retention
#1519265 RESOLVED Policy Compliance Opened 2019-01-10 · Closed 2025-08-18 · 42% similar
QuoVadis: Recap of BR Compliance in 2018 issuance by external subCAs
#1518560 RESOLVED Policy Compliance Opened 2019-01-08 · Closed 2023-02-22 · 42% similar
Asseco DS / Certum: Use of forbidden subjectPublicKeyInfo algorithm

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action