← HARICA cases
Bugzilla #1942130 Certificate Problem Report

HARICA: S/MIME certificate issuance without proper validation

RESOLVED FIXED HARICA
AI Summary

HARICA identified a flaw in their S/MIME certificate issuance process that allowed mailbox-validated certificates to be issued without proper email address validation. This issue arose from a recent update to their REST API on January 8, 2025. Upon receiving a report on January 15, HARICA quickly deployed a patch and revoked five mis-issued certificates within 24 hours. The root cause was traced to inadequate testing of the new API functionality. HARICA has since implemented a central validation checkpoint to prevent similar issues in the future.

Model: gpt-4o-mini Generated: 2026-06-13 21:14 UTC Confidence: 0.95
Chronology
  1. Received a certificate problem report from a Subscriber.
  2. Confirmed the bug and deployed a patch.
  3. Revoked five mis-issued certificates.
  4. Completed refactoring code to implement a central validation checkpoint.
  5. Incident report closure summary provided.
Participants
Dimitris Zacharopoulos bwilson@mozilla.com
External References
Similar Local Cases
#1535772 RESOLVED Certificate Problem Report Opened 2019-03-15 · Closed 2023-02-22 · 59% similar
HARICA: wrong characters in NC extension of Technically Constrained Intermediate CA Certificates
#1878106 RESOLVED Certificate Problem Report Opened 2024-02-01 · Closed 2024-03-08 · 59% similar
HARICA: Anomaly in OCSP services after CA software upgrade
#1963629 RESOLVED Certificate Problem Report Opened 2025-04-30 · Closed 2025-07-08 · 57% similar
HARICA: One of the two Certificate Problem Report email aliases not working
#1535509 RESOLVED Certificate Problem Report Opened 2019-03-15 · Closed 2023-02-22 · 57% similar
HARICA: Insufficient serial number entropy
#1580393 RESOLVED Certificate Problem Report Opened 2019-09-11 · Closed 2022-11-14 · 56% similar
HARICA: OCSP Responder Returned "Unauthorized" for Some Precertificates
#1649945 RESOLVED Certificate Problem Report Opened 2020-07-02 · Closed 2023-02-22 · 56% similar
HARICA: Incorrect OCSP Delegated Responder Certificate
#1699796 RESOLVED Certificate Problem Report Opened 2021-03-19 · Closed 2023-02-22 · 56% similar
HARICA: Certificates with invalid policy tree
#1736020 RESOLVED Certificate Problem Report Opened 2021-10-15 · Closed 2023-02-22 · 54% similar
Telia: Invalid email contact address was used for few domains

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action