← HARICA cases
Bugzilla #1872374 Certificate Misissuance

HARICA: subject:organizationIdentifier using VATEL as a prefix for tax identifier

RESOLVED FIXED HARICA
AI Summary

HARICA identified a misissuance of three EV TLS Certificates that used 'VATEL' as a prefix for the 'subject:organizationIdentifier', which conflicts with the EV Guidelines requiring the ISO 3166-1 country code. Although Greek law allows the use of 'EL', the EV Guidelines mandate the use of 'GR'. Following community feedback, HARICA decided to revoke the affected certificates and update their policies to ensure compliance with both local law and the EV Guidelines. The situation highlights the complexities of aligning local regulations with international standards.

Model: gpt-4o-mini Generated: 2026-06-13 21:14 UTC Confidence: 0.90
Chronology
  1. CP/CPS version 3.8 published introducing the organizationIdentifier attribute.
  2. HARICA receives guidance from the Greek eIDAS Supervisory Body on preferred prefixes.
  3. HARICA discloses the issue and seeks community feedback.
  4. HARICA decides to revoke the misissued certificates.
  5. Last misissued certificate revoked.
  6. HARICA proposes a new CA/B Forum ballot to amend the EV Guidelines.
Participants
Dimitris Zacharopoulos Aaron Clint C. Clements
Similar Local Cases
#1943596 RESOLVED Certificate Misissuance Opened 2025-01-24 · Closed 2025-05-01 · 57% similar
HARICA: S/MIME certificate issuance with incorrect commonName
#1943604 RESOLVED Certificate Misissuance Opened 2025-01-24 · Closed 2025-05-25 · 55% similar
HARICA: TLS Server certificate issuance without proper validation
#1597135 RESOLVED Certificate Misissuance Opened 2019-11-17 · Closed 2023-02-22 · 55% similar
HARICA: 3 EV TLS Certificates without L or ST
#1590723 RESOLVED Certificate Misissuance Opened 2019-10-23 · Closed 2024-05-09 · 41% similar
Consorci AOC: Misissued certificates: commonName:organizationIdentifier attribute inclusion not conforming CABForum guidelines 1.6.9
#1936906 RESOLVED Certificate Misissuance Opened 2024-12-12 · Closed 2025-02-14 · 40% similar
DigiCert: Invalid Characters in S/MIME Subject Fields
#2012101 RESOLVED Certificate Misissuance Opened 2026-01-23 · Closed 2026-04-06 · 40% similar
Telia: S/MIME Misissuance - incorrect subject information for Multipurpose sponsor-validated-profile
#1860750 RESOLVED Certificate Misissuance Opened 2023-10-24 · Closed 2023-11-08 · 40% similar
SwissSign: EV code in JurisdiktionStateOrProvinceName
#1914020 RESOLVED Certificate Misissuance Opened 2024-08-20 · Closed 2024-09-13 · 40% similar
SwissSign: S/MIME NCP non ASCII symbols in email and SAN field wrong coding

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action