← eMudhra Technologies Limited cases
Bugzilla #1999241 Incident Repository Issue

eMudhra emSign PKI Services: Delayed publication of issuing CA certificates in CCADB

RESOLVED FIXED eMudhra Technologies Limited
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case is an incident disclosure by eMudhra regarding delayed publication of certain issuing and cross-sign CA certificates in the Common CA Database (CCADB). The certificates (emSign TLS CA – G1 and G3 issuing CAs, and emSign Root TLS CA – G3 and G1 cross-sign CAs) were created on 2024-07-11 as part of eMudhra’s CA hierarchy design for browser root program evaluation. Under Section 8 of the Google Chrome Root Program Policy v1.5, eMudhra stated that issuing CAs must be uploaded to CCADB within seven days of creation, but the issuing CAs were uploaded on 2024-09-16 and the cross-sign CAs on 2024-09-23. eMudhra said the non-compliance was identified on 2025-11-09 during Chrome’s metadata verification activities, and eMudhra submitted the incident disclosure in response. eMudhra reported that the affected CAs had not been used for any active issuance during the non-compliance period, and therefore no impact occurred to relying parties or production infrastructure. eMudhra also described remediation steps including centralized accountability for CCADB updates, a mandatory maker/checker workflow with checklist enforcement, embedding a “publish to CCADB within 7 days” checkpoint into the issuing-CA creation runbook with publication-log tracking, and refresher training. The bug was resolved as FIXED, with a report closure summary stating all action items were completed and requesting closure.

Model: gpt-5.4-nano Generated: 2026-06-13 21:31 UTC Revised: 2026-06-16 18:43 UTC Confidence: 0.90 9 comments
Chronology
  1. eMudhra created two issuing CA certificates and two cross-sign CA certificates as part of its CA hierarchy design for browser root program evaluation.
  2. eMudhra uploaded the issuing CA certificates to CCADB.
  3. eMudhra uploaded the cross-sign CA certificates to CCADB.
  4. Chrome metadata verification identified the CCADB publication delay.
  5. eMudhra opened the incident disclosure bug in Mozilla Bugzilla.
  6. eMudhra submitted a report closure summary stating action items were completed and requested closure.
Thread Activity
  1. Emudhra representative — Created the incident report describing the delayed CCADB publication timeline, stated the non-compliance was identified via Chrome metadata verification, and provided remediation details.
  2. Emudhra representative — Responded to questions about why the incident was overlooked, explaining a decentralized responsibility model and describing corrective changes made after Bug 1965559.
  3. Emudhra representative — Provided a weekly status update listing completed action items such as establishing a mandatory maker/checker workflow, adding CCADB publication tracking, and conducting refresher training.
  4. Emudhra representative — Reported no further action required at that time.
  5. Emudhra representative — Reported no further action required at that time.
  6. CCADB representative — Noted that all action items were marked completed and asked for a closure report if ready to close.
  7. Emudhra representative — Submitted a report closure summary reiterating the incident timeline, impact statement, remediation measures, and requested closure.
  8. CCADB representative — Issued a final call for comments and indicated the report would be closed approximately 2025-12-24.
Participants
Emudhra representative Community commenter CCADB representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#2007297 RESOLVED Incident Repository Issue Opened 2025-12-21 · Closed 2026-02-23 · 99% similar
eMudhra emSign PKI Services: CRL URL Mismatch Between CCADB Disclosure and Issued Certificates
#1965559 RESOLVED Repository Issue Opened 2025-05-09 · Closed 2025-07-01 · 98% similar
eMudhra: Delayed Publication of Issuing CA Certificates In CCADB
#2009491 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Repository Issue Opened 2026-01-09 · Closed 2026-02-17 · 87% similar
DigiCert: Several non-functioning AIA URLs
#2009543 RESOLVED Ca Certificate Compliance Incident Repository Issue Opened 2026-01-10 · Closed 2026-02-09 · 78% similar
Microsoft PKI Services: Improper Disclosure of CRLs – Does Not Match CA Subject
#2009542 RESOLVED Ca Certificate Compliance Incident Repository Issue Opened 2026-01-10 · Closed 2026-02-17 · 78% similar
Microsoft PKI Services: Improper Disclosure of CRLs – IDP – New CAs
#1821508 RESOLVED Incident Opened 2023-03-09 · Closed 2024-06-30 · 78% similar
eMudhra: CRL occasionally unavailable and returns 404 error
#2009545 RESOLVED Ca Certificate Compliance Incident Repository Issue Opened 2026-01-10 · Closed 2026-02-11 · 77% similar
Microsoft PKI Services: Improper Disclosure of CRLs – Protocol Scheme
#2014610 RESOLVED Self Reported Incident Incident Opened 2026-02-05 · Closed 2026-04-11 · 77% similar
IdenTrust: Root OCSP Signer certificate mis-issuance

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action