← HARICA cases
Bugzilla #1699796 Self Reported Incident Certificate Misissuance

HARICA: Certificates with invalid policy tree

RESOLVED FIXED HARICA
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

HARICA reported an incident after its internal checks identified 33 non-expired, non-revoked TLS certificates issued from a legacy issuing CA that stopped issuing certificates in May 2019. The certificates were issued with a policy identifier not included in the issuing CA’s certificatePolicies extension, and the extension did not include the “anyPolicy” OID. HARICA said it became aware of the issue through participation in the CA/B Forum Server Certificate Working Group Validation subcommittee, where a discussion raised a concern related to RFC 5280’s certificate path validation algorithm. HARICA contacted Chrome and Mozilla Root program teams to search for a compliant remediation that would not require revocation, and it contacted subscribers to prepare for certificate replacement within 5 days if remediation was not feasible. HARICA ultimately revoked the affected certificates on 2021-03-24 and submitted a final report on 2021-03-30. The bug was marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:12 UTC Revised: 2026-06-16 19:14 UTC Confidence: 0.90 9 comments
Chronology
  1. Discussion in the CA/B Forum validation subcommittee raised an alarm leading HARICA to investigate a potential certificate policies non-compliance.
  2. HARICA reviewed RFC 5280 and performed internal checks identifying 33 affected TLS certificates.
  3. HARICA posted an initial incident report in Bugzilla and contacted root program teams and affected subscribers.
  4. HARICA revoked the affected certificates.
  5. HARICA submitted the final report to Bugzilla.
Thread Activity
  1. HARICA — HARICA reported that internal checks found 33 TLS certificates with a certificatePolicies non-compliance (missing policy identifier and missing anyPolicy OID) and said they were scheduled for revocation within 5 days unless other solutions were proposed.
  2. HARICA — HARICA provided a preliminary incident report timeline and stated the affected certificates were revoked.
  3. Community commenter — Paul commented that the revocation timing appeared to miss the deadline based on the dates in HARICA’s timeline.
  4. HARICA — HARICA replied that the non-compliance was confirmed on 2021-03-19 after investigation.
  5. HARICA — HARICA posted its final report with the incident timeline and stated that issuance by the affected issuing CA had stopped since 2019-05-13 and that all actively issuing CA certificates have the anyPolicy OID.
  6. Community commenter — Paul reiterated concerns about the timeline between confirmation and revocation.
  7. Community commenter — Ryan discussed considerations around investigation timing versus certificate problem report timelines and noted HARICA’s proactive steps.
  8. HARICA — HARICA responded that it treated the issue as a responsible practice under Baseline Requirements response expectations for a Certificate Problem Report and agreed to include time-of-day in future reports.
  9. Mozilla representative — Mozilla indicated the case would be closed next Wednesday unless other issues remained to discuss.
Participants
HARICA Community commenter Mozilla representative
Similar Local Cases
#1943596 RESOLVED Certificate Misissuance Delayed Revocation Opened 2025-01-24 · Closed 2025-05-01 · 97% similar
HARICA: S/MIME certificate issuance with incorrect commonName
#1649945 RESOLVED Self Reported Incident Opened 2020-07-02 · Closed 2023-02-22 · 95% similar
HARICA: Incorrect OCSP Delegated Responder Certificate
#2029643 RESOLVED Self Reported Incident Revocation Issue Certificate Misissuance Opened 2026-04-06 · Closed 2026-05-22 · 90% similar
HARICA: Incorrect Open MPIC Lambda implementation by EJBCA ACME Service
#1535772 RESOLVED Incident Certificate Misissuance Revocation Issue Opened 2019-03-15 · Closed 2023-02-22 · 89% similar
HARICA: wrong characters in NC extension of Technically Constrained Intermediate CA Certificates
#1530971 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-02-27 · Closed 2023-02-22 · 88% similar
HARICA: P-384,ecdsa-with-SHA256 Certificates
#1535509 RESOLVED Incident Certificate Misissuance Revocation Issue Opened 2019-03-15 · Closed 2023-02-22 · 88% similar
HARICA: Insufficient serial number entropy
#1872374 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2023-12-29 · Closed 2026-06-10 · 88% similar
HARICA: subject:organizationIdentifier using VATEL as a prefix for tax identifier
#1708834 RESOLVED Certificate Misissuance Self Reported Incident Opened 2021-04-30 · Closed 2023-02-22 · 87% similar
GlobalSign: Invalid stateOrProvinceName and locality pair

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action