← HARICA cases
Bugzilla #2017845 Certificate Misissuance Self Reported Incident Problem Reporting Failure

HARICA: Incorrect nCAId in PSD2 QCStatement for QWACs

RESOLVED FIXED HARICA
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

HARICA reported an incident involving PSD2 Qualified Website Authentication Certificates (QWACs) where a manual issuance process incorrectly populated the PSD2 QCStatement extension `nCAId` field. HARICA stated that the affected certificates included an erroneous `PSD` prefix (e.g., `PSDFR-ACPR` instead of `FR-ACPR`), which HARICA said did not follow the structure required by ETSI TS 119 495 §5.2.3 GEN-5.2.3-2. HARICA identified four affected QWACs and stated that they were replaced and revoked within five days, with no remaining valid certificates. HARICA attributed the root cause to a deficiency in the manual certificate issuance workflow, where validation personnel carried over the `PSD` prefix into the `nCAId` field and the issuance instructions did not sufficiently distinguish between the organization identifier format and the ETSI-defined encoding requirements. As remediation, HARICA updated manual validation and issuance procedures to explicitly highlight the proper `nCAId` encoding requirements and to prohibit inclusion of prefixes in that field, and notified the validation team. HARICA also reported progress on permanent process improvements, including implementing PKI Metal and a fully automated workflow in the HARICA RA Portal. In the latest thread activity, HARICA posted a report closure summary stating all disclosed action items were completed and requested closure, and CCADB issued a final call for comments before closure.

Model: gpt-5.4-nano Generated: 2026-06-13 21:16 UTC Revised: 2026-07-04 18:20 UTC Confidence: 0.86 9 comments
Chronology
  1. A PSD2 QWAC was issued with an incorrect value in the PSD2 QCStatement `nCAId` field.
  2. HARICA confirmed the issue and scheduled revocation within five days.
  3. HARICA posted the full incident report describing impact and remediation actions.
  4. HARICA posted a report closure summary stating all disclosed action items were completed and requested closure.
  5. CCADB issued a final call for comments before closing the incident report.
Thread Activity
  1. HARICA — HARICA submitted a preliminary incident report describing the incorrect `nCAId` encoding (erroneous `PSD` prefix), identifying four affected non-revoked, non-expired QWACs, and stating replacement and revocation would proceed within five days while updating manual validation instructions.
  2. HARICA — HARICA posted the full incident report stating the issue was due to a deficiency in the manual issuance workflow, that four affected certificates were replaced and revoked within five days, and that manual validation instructions and preventive measures were updated.
  3. HARICA — HARICA requested setting the next update to 2026-03-27.
  4. HARICA — HARICA provided an action-items update table showing manual instruction improvements and PKI Metal as completed, with the fully automated RA Portal workflow ongoing.
  5. HARICA — HARICA reported the initial code for the fully automated workflow was committed and in code review along with QA testing.
  6. HARICA — HARICA reported the fully automated workflow in the RA Portal as completed and asked if there were additional questions or concerns.
  7. HARICA — HARICA posted a report closure summary stating the incident details, remediation steps, and that all disclosed action items were completed, requesting closure.
  8. CCADB representative — CCADB posted a final call for comments or questions and stated the incident report would be closed on approximately 2026-06-29.
Participants
HARICA CCADB representative
External References
Similar Local Cases
#2029643 RESOLVED Self Reported Incident Revocation Issue Certificate Misissuance Opened 2026-04-06 · Closed 2026-05-22 · 98% similar
HARICA: Incorrect Open MPIC Lambda implementation by EJBCA ACME Service
#2056668 UNCONFIRMED Policy Document Issue Incident Self Reported Incident Certificate Misissuance Opened 2026-07-21 Still Open · 89% similar
HARICA: Issuance of Server TLS Certificates without AIA OCSP URI against CP/CPS
#1943604 RESOLVED Certificate Misissuance Opened 2025-01-24 · Closed 2025-05-25 · 84% similar
HARICA: TLS Server certificate issuance without proper validation
#2032063 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-04-15 · Closed 2026-07-06 · 80% similar
Hongkong Post: Certificates with invalid embedded SCT signature
#1979475 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-07-26 · Closed 2026-01-20 · 80% similar
Microsoft PKI Services: End Entity Certificate Mis-issuance against CPS (BasicConstraints)
#2005939 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-12-14 · Closed 2026-03-13 · 80% similar
Microsec: CT Logging mistakes
#1699796 RESOLVED Self Reported Incident Certificate Misissuance Opened 2021-03-19 · Closed 2023-02-22 · 80% similar
HARICA: Certificates with invalid policy tree
#2026351 RESOLVED Self Reported Incident Certificate Misissuance Opened 2026-03-25 · Closed 2026-05-18 · 79% similar
Identrust: Root CrossSign, of dedicated Roots, missing EKU

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action