eMudhra emSign PKI Services: Delayed publication of issuing CA certificates in CCADB
This case is an incident disclosure by eMudhra regarding delayed publication of certain issuing and cross-sign CA certificates in the Common CA Database (CCADB). The certificates (emSign TLS CA – G1 and G3 issuing CAs, and emSign Root TLS CA – G3 and G1 cross-sign CAs) were created on 2024-07-11 as part of eMudhra’s CA hierarchy design for browser root program evaluation. Under Section 8 of the Google Chrome Root Program Policy v1.5, eMudhra stated that issuing CAs must be uploaded to CCADB within seven days of creation, but the issuing CAs were uploaded on 2024-09-16 and the cross-sign CAs on 2024-09-23. eMudhra said the non-compliance was identified on 2025-11-09 during Chrome’s metadata verification activities, and eMudhra submitted the incident disclosure in response. eMudhra reported that the affected CAs had not been used for any active issuance during the non-compliance period, and therefore no impact occurred to relying parties or production infrastructure. eMudhra also described remediation steps including centralized accountability for CCADB updates, a mandatory maker/checker workflow with checklist enforcement, embedding a “publish to CCADB within 7 days” checkpoint into the issuing-CA creation runbook with publication-log tracking, and refresher training. The bug was resolved as FIXED, with a report closure summary stating all action items were completed and requesting closure.
- eMudhra created two issuing CA certificates and two cross-sign CA certificates as part of its CA hierarchy design for browser root program evaluation.
- eMudhra uploaded the issuing CA certificates to CCADB.
- eMudhra uploaded the cross-sign CA certificates to CCADB.
- Chrome metadata verification identified the CCADB publication delay.
- eMudhra opened the incident disclosure bug in Mozilla Bugzilla.
- eMudhra submitted a report closure summary stating action items were completed and requested closure.
- Emudhra representative — Created the incident report describing the delayed CCADB publication timeline, stated the non-compliance was identified via Chrome metadata verification, and provided remediation details.
- Emudhra representative — Responded to questions about why the incident was overlooked, explaining a decentralized responsibility model and describing corrective changes made after Bug 1965559.
- Emudhra representative — Provided a weekly status update listing completed action items such as establishing a mandatory maker/checker workflow, adding CCADB publication tracking, and conducting refresher training.
- Emudhra representative — Reported no further action required at that time.
- Emudhra representative — Reported no further action required at that time.
- CCADB representative — Noted that all action items were marked completed and asked for a closure report if ready to close.
- Emudhra representative — Submitted a report closure summary reiterating the incident timeline, impact statement, remediation measures, and requested closure.
- CCADB representative — Issued a final call for comments and indicated the report would be closed approximately 2025-12-24.