← HARICA cases
Bugzilla #1872374 Ca Certificate Compliance Certificate Misissuance

HARICA: EV TLS/eIDAS QWAC mis-issued subject:organizationIdentifier using VATEL/EL for Greece; revoked within 5 days

RESOLVED FIXED HARICA
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

HARICA reported a potentially problematic incident discovered during an internal quality check after enabling a new linter. HARICA found that three EV TLS Certificates that were also Qualified Website Authentication Certificates under eIDAS were issued with a subject:organizationIdentifier using the "VAT" registration scheme with the country identifier "EL", which HARICA stated is not the alpha-2 country code for Greece per ISO 3166-1. HARICA said the EV Guidelines require the organizationIdentifier value to include the 2-character ISO 3166 country code, but HARICA also described an exception for Greece in ETSI EN 319 412-1 and guidance from the Greek eIDAS Supervisory Body recommending VATEL/TINEL. After community feedback, HARICA decided the certificates were mis-issued because it did not follow the procedures in section 9.16.3 of the TLS Baseline Requirements and section 8.1 of the EV Guidelines. HARICA stated that the two unexpired/unrevoked certificates would be revoked within 5 days, and it later reported that the last mis-issued certificate was revoked. HARICA also reported proposing a CA/B Forum ballot to amend the EV Guidelines accordingly and stated that this completes its remediation actions for the bug.

Model: gpt-5.4-nano Generated: 2026-06-13 21:14 UTC Revised: 2026-06-16 19:15 UTC Confidence: 0.90 10 comments
Chronology
  1. HARICA enabled pre-issuance linting and began issuing certificates using its configured organizationIdentifier handling.
  2. A QWAC renewal attempt failed due to the same organizationIdentifier linter error regarding the VATEL prefix.
  3. HARICA opened the bug after identifying the potentially problematic certificate issuance during an internal quality check.
  4. HARICA completed the decision to revoke affected certificates and revoked the remaining unexpired mis-issued certificate(s).
  5. HARICA reported proposing a CA/B Forum ballot to amend the EV Guidelines and said remediation was complete.
Thread Activity
  1. HARICA — HARICA described an incident where three EV TLS/eIDAS QWAC certificates used subject:organizationIdentifier with VAT/EL for Greece and explained the perceived legal/standards conflict.
  2. Internet Security Research Group — Aaron questioned the interpretation of the local-law "may"/"strongly recommended" language versus EV Guidelines "MUST" and asked whether HARICA would file a separate revocation failure incident.
  3. HARICA — Dimitris responded that HARICA was relying on section 9.16.3 BRs and would wait for community feedback before making a final revocation determination.
  4. Apple representative — Clint asked for documentation supporting HARICA’s interpretation and noted that the certificates appeared not to be issued in accordance with the TLS BRs.
  5. Google representative — Cclements said revocation seemed appropriate for non-compliance with the EV Guidelines and that HARICA’s CPS stance required policy procedures before issuance.
  6. HARICA — HARICA updated the incident report, stated community agreement that the certificates were mis-issued, and said the unexpired certificates would be revoked within 5 days.
  7. HARICA — HARICA listed updated action items, including revoking the last mis-issued certificate and engaging with CA/B Forum WGs.
  8. HARICA — HARICA reported proposing a CA/B Forum ballot to amend the EV Guidelines and stated remediation actions were complete.
Participants
HARICA Internet Security Research Group Apple representative Google representative
Similar Local Cases
#1530971 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-02-27 · Closed 2023-02-22 · 89% similar
HARICA: P-384,ecdsa-with-SHA256 Certificates
#1699796 RESOLVED Self Reported Incident Certificate Misissuance Opened 2021-03-19 · Closed 2023-02-22 · 88% similar
HARICA: Certificates with invalid policy tree
#1943596 RESOLVED Certificate Misissuance Delayed Revocation Opened 2025-01-24 · Closed 2025-05-01 · 88% similar
HARICA: S/MIME certificate issuance with incorrect commonName
#1535509 RESOLVED Incident Certificate Misissuance Revocation Issue Opened 2019-03-15 · Closed 2023-02-22 · 87% similar
HARICA: Insufficient serial number entropy
#1535772 RESOLVED Incident Certificate Misissuance Revocation Issue Opened 2019-03-15 · Closed 2023-02-22 · 87% similar
HARICA: wrong characters in NC extension of Technically Constrained Intermediate CA Certificates
#1597135 RESOLVED Certificate Misissuance Revocation Issue Incident Opened 2019-11-17 · Closed 2023-02-22 · 80% similar
HARICA: 3 EV TLS Certificates without L or ST
#2029643 RESOLVED Self Reported Incident Revocation Issue Certificate Misissuance Opened 2026-04-06 · Closed 2026-05-22 · 80% similar
HARICA: Incorrect Open MPIC Lambda implementation by EJBCA ACME Service
#2017845 RESOLVED Certificate Misissuance Self Reported Incident Problem Reporting Failure Opened 2026-02-19 · Closed 2026-06-29 · 79% similar
HARICA: Incorrect nCAId in PSD2 QCStatement for QWACs

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action