← HARICA cases
Bugzilla #1699796
Certificate Problem Report
HARICA: Certificates with invalid policy tree
RESOLVED
FIXED
HARICA
AI Summary
HARICA identified 33 non-expired TLS certificates issued with invalid policy identifiers not included in the Issuing CA's certificatePolicies extension. These certificates were from a legacy CA that ceased operations in May 2019. Following internal checks and discussions within the CA/B Forum, HARICA confirmed the non-compliance and scheduled revocation of the affected certificates within five days. The certificates were ultimately revoked on March 24, 2021, after a thorough investigation and outreach to affected subscribers.
Chronology
- Discussion at CA/B Forum raises alarm for further investigation
- Internal checks identify 33 non-compliant certificates
- Initial incident report filed in Bugzilla
- Affected certificates revoked
Participants
Dimitris Zacharopoulos
External References
Similar Local Cases
HARICA: Insufficient serial number entropy
HARICA: Anomaly in OCSP services after CA software upgrade
HARICA: wrong characters in NC extension of Technically Constrained Intermediate CA Certificates
HARICA: OCSP Responder Returned "Unauthorized" for Some Precertificates
HARICA: Incorrect OCSP Delegated Responder Certificate
HARICA: One of the two Certificate Problem Report email aliases not working
HARICA: S/MIME certificate issuance without proper validation
HARICA: Incorrect nCAId in PSD2 QCStatement for QWACs