HARICA: Incorrect nCAId in PSD2 QCStatement for QWACs
HARICA reported an incident involving PSD2 Qualified Website Authentication Certificates (QWACs) where a manual issuance process incorrectly populated the PSD2 QCStatement extension `nCAId` field. HARICA stated that the affected certificates included an erroneous `PSD` prefix (e.g., `PSDFR-ACPR` instead of `FR-ACPR`), which HARICA said did not follow the structure required by ETSI TS 119 495 §5.2.3 GEN-5.2.3-2. HARICA identified four affected QWACs and stated that they were replaced and revoked within five days, with no remaining valid certificates. HARICA attributed the root cause to a deficiency in the manual certificate issuance workflow, where validation personnel carried over the `PSD` prefix into the `nCAId` field and the issuance instructions did not sufficiently distinguish between the organization identifier format and the ETSI-defined encoding requirements. As remediation, HARICA updated manual validation and issuance procedures to explicitly highlight the proper `nCAId` encoding requirements and to prohibit inclusion of prefixes in that field, and notified the validation team. HARICA also reported progress on permanent process improvements, including implementing PKI Metal and a fully automated workflow in the HARICA RA Portal. In the latest thread activity, HARICA posted a report closure summary stating all disclosed action items were completed and requested closure, and CCADB issued a final call for comments before closure.
- A PSD2 QWAC was issued with an incorrect value in the PSD2 QCStatement `nCAId` field.
- HARICA confirmed the issue and scheduled revocation within five days.
- HARICA posted the full incident report describing impact and remediation actions.
- HARICA posted a report closure summary stating all disclosed action items were completed and requested closure.
- CCADB issued a final call for comments before closing the incident report.
- HARICA — HARICA submitted a preliminary incident report describing the incorrect `nCAId` encoding (erroneous `PSD` prefix), identifying four affected non-revoked, non-expired QWACs, and stating replacement and revocation would proceed within five days while updating manual validation instructions.
- HARICA — HARICA posted the full incident report stating the issue was due to a deficiency in the manual issuance workflow, that four affected certificates were replaced and revoked within five days, and that manual validation instructions and preventive measures were updated.
- HARICA — HARICA requested setting the next update to 2026-03-27.
- HARICA — HARICA provided an action-items update table showing manual instruction improvements and PKI Metal as completed, with the fully automated RA Portal workflow ongoing.
- HARICA — HARICA reported the initial code for the fully automated workflow was committed and in code review along with QA testing.
- HARICA — HARICA reported the fully automated workflow in the RA Portal as completed and asked if there were additional questions or concerns.
- HARICA — HARICA posted a report closure summary stating the incident details, remediation steps, and that all disclosed action items were completed, requesting closure.
- CCADB representative — CCADB posted a final call for comments or questions and stated the incident report would be closed on approximately 2026-06-29.