HARICA: EV TLS/eIDAS QWAC mis-issued subject:organizationIdentifier using VATEL/EL for Greece; revoked within 5 days
HARICA reported a potentially problematic incident discovered during an internal quality check after enabling a new linter. HARICA found that three EV TLS Certificates that were also Qualified Website Authentication Certificates under eIDAS were issued with a subject:organizationIdentifier using the "VAT" registration scheme with the country identifier "EL", which HARICA stated is not the alpha-2 country code for Greece per ISO 3166-1. HARICA said the EV Guidelines require the organizationIdentifier value to include the 2-character ISO 3166 country code, but HARICA also described an exception for Greece in ETSI EN 319 412-1 and guidance from the Greek eIDAS Supervisory Body recommending VATEL/TINEL. After community feedback, HARICA decided the certificates were mis-issued because it did not follow the procedures in section 9.16.3 of the TLS Baseline Requirements and section 8.1 of the EV Guidelines. HARICA stated that the two unexpired/unrevoked certificates would be revoked within 5 days, and it later reported that the last mis-issued certificate was revoked. HARICA also reported proposing a CA/B Forum ballot to amend the EV Guidelines accordingly and stated that this completes its remediation actions for the bug.
- HARICA enabled pre-issuance linting and began issuing certificates using its configured organizationIdentifier handling.
- A QWAC renewal attempt failed due to the same organizationIdentifier linter error regarding the VATEL prefix.
- HARICA opened the bug after identifying the potentially problematic certificate issuance during an internal quality check.
- HARICA completed the decision to revoke affected certificates and revoked the remaining unexpired mis-issued certificate(s).
- HARICA reported proposing a CA/B Forum ballot to amend the EV Guidelines and said remediation was complete.
- HARICA — HARICA described an incident where three EV TLS/eIDAS QWAC certificates used subject:organizationIdentifier with VAT/EL for Greece and explained the perceived legal/standards conflict.
- Internet Security Research Group — Aaron questioned the interpretation of the local-law "may"/"strongly recommended" language versus EV Guidelines "MUST" and asked whether HARICA would file a separate revocation failure incident.
- HARICA — Dimitris responded that HARICA was relying on section 9.16.3 BRs and would wait for community feedback before making a final revocation determination.
- Apple representative — Clint asked for documentation supporting HARICA’s interpretation and noted that the certificates appeared not to be issued in accordance with the TLS BRs.
- Google representative — Cclements said revocation seemed appropriate for non-compliance with the EV Guidelines and that HARICA’s CPS stance required policy procedures before issuance.
- HARICA — HARICA updated the incident report, stated community agreement that the certificates were mis-issued, and said the unexpired certificates would be revoked within 5 days.
- HARICA — HARICA listed updated action items, including revoking the last mis-issued certificate and engaging with CA/B Forum WGs.
- HARICA — HARICA reported proposing a CA/B Forum ballot to amend the EV Guidelines and stated remediation actions were complete.