← HARICA cases
Bugzilla #1943604 Certificate Misissuance

HARICA: TLS Server certificate issuance without proper validation

RESOLVED FIXED HARICA
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

On January 23, 2025, HARICA was informed that a TLS Server certificate was issued without proper domain control validation due to a typo in the domain name. This led to a flaw in the validation code that allowed unvalidated domains to reuse domain control validation (DCV) evidence. HARICA suspended TLS certificate issuance, revoked the affected certificate within 24 hours, and implemented a fix the same day. A full audit confirmed no other certificates were affected. HARICA has committed to improving their validation processes and conducting further testing to prevent similar issues in the future.

Model: gpt-4o-mini Generated: 2026-06-13 21:15 UTC Revised: 2026-06-16 19:17 UTC Confidence: 0.90 14 comments
Chronology
  1. HARICA was informed of a misissued TLS Server certificate.
  2. The affected certificate was revoked.
  3. HARICA submitted a closure summary for the incident.
Thread Activity
  1. HARICA — HARICA was informed by a Subscriber that a TLS Server certificate was issued without proper domain control validation.
  2. HARICA — An incident report was submitted detailing the misissuance and the flaw in the validation code.
  3. HARICA — HARICA submitted an incident closure summary outlining the root cause and remediation steps.
Participants
HARICA CCADB representative
External References
Similar Local Cases
#2029643 RESOLVED Self Reported Incident Revocation Issue Certificate Misissuance Opened 2026-04-06 · Closed 2026-05-22 · 94% similar
HARICA: Incorrect Open MPIC Lambda implementation by EJBCA ACME Service
#2056668 RESOLVED Self Reported Incident Policy Document Issue Incident Opened By Ca Opened 2026-07-21 · Closed 2026-08-31 · 85% similar
HARICA: Issuance of Server TLS Certificates without AIA OCSP URI against CP/CPS
#2017845 RESOLVED Certificate Misissuance Self Reported Incident Problem Reporting Failure Opened 2026-02-19 · Closed 2026-07-28 · 84% similar
HARICA: Incorrect nCAId in PSD2 QCStatement for QWACs
#1597135 RESOLVED Certificate Misissuance Revocation Issue Incident Opened 2019-11-17 · Closed 2023-02-22 · 81% similar
HARICA: 3 EV TLS Certificates without L or ST
#1699796 RESOLVED Self Reported Incident Certificate Misissuance Opened 2021-03-19 · Closed 2023-02-22 · 79% similar
HARICA: Certificates with invalid policy tree
#1943596 RESOLVED Certificate Misissuance Delayed Revocation Opened 2025-01-24 · Closed 2026-07-28 · 79% similar
HARICA: S/MIME certificate issuance with incorrect commonName
#1535509 RESOLVED Incident Certificate Misissuance Revocation Issue Opened 2019-03-15 · Closed 2026-07-28 · 78% similar
HARICA: Insufficient serial number entropy
#1535772 RESOLVED Incident Certificate Misissuance Revocation Issue Opened 2019-03-15 · Closed 2026-07-28 · 77% similar
HARICA: wrong characters in NC extension of Technically Constrained Intermediate CA Certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action