HARICA: Certificates with invalid policy tree
HARICA reported an incident after its internal checks identified 33 non-expired, non-revoked TLS certificates issued from a legacy issuing CA that stopped issuing certificates in May 2019. The certificates were issued with a policy identifier not included in the issuing CA’s certificatePolicies extension, and the extension did not include the “anyPolicy” OID. HARICA said it became aware of the issue through participation in the CA/B Forum Server Certificate Working Group Validation subcommittee, where a discussion raised a concern related to RFC 5280’s certificate path validation algorithm. HARICA contacted Chrome and Mozilla Root program teams to search for a compliant remediation that would not require revocation, and it contacted subscribers to prepare for certificate replacement within 5 days if remediation was not feasible. HARICA ultimately revoked the affected certificates on 2021-03-24 and submitted a final report on 2021-03-30. The bug was marked RESOLVED with resolution FIXED.
- Discussion in the CA/B Forum validation subcommittee raised an alarm leading HARICA to investigate a potential certificate policies non-compliance.
- HARICA reviewed RFC 5280 and performed internal checks identifying 33 affected TLS certificates.
- HARICA posted an initial incident report in Bugzilla and contacted root program teams and affected subscribers.
- HARICA revoked the affected certificates.
- HARICA submitted the final report to Bugzilla.
- HARICA — HARICA reported that internal checks found 33 TLS certificates with a certificatePolicies non-compliance (missing policy identifier and missing anyPolicy OID) and said they were scheduled for revocation within 5 days unless other solutions were proposed.
- HARICA — HARICA provided a preliminary incident report timeline and stated the affected certificates were revoked.
- Community commenter — Paul commented that the revocation timing appeared to miss the deadline based on the dates in HARICA’s timeline.
- HARICA — HARICA replied that the non-compliance was confirmed on 2021-03-19 after investigation.
- HARICA — HARICA posted its final report with the incident timeline and stated that issuance by the affected issuing CA had stopped since 2019-05-13 and that all actively issuing CA certificates have the anyPolicy OID.
- Community commenter — Paul reiterated concerns about the timeline between confirmation and revocation.
- Community commenter — Ryan discussed considerations around investigation timing versus certificate problem report timelines and noted HARICA’s proactive steps.
- HARICA — HARICA responded that it treated the issue as a responsible practice under Baseline Requirements response expectations for a Certificate Problem Report and agreed to include time-of-day in future reports.
- Mozilla representative — Mozilla indicated the case would be closed next Wednesday unless other issues remained to discuss.