HARICA: Incorrect Open MPIC Lambda implementation by EJBCA ACME Service
HARICA reported a compliance incident involving its EJBCA ACME service implementation of MPIC (Multi-Perspective Issuance Corroboration). HARICA said it noticed a preliminary incident report from another CA and then investigated, finding that after MPIC was enabled the CA software relied only on MPIC for DCV and did not execute DCV actions from the Primary Network Perspective as it did before MPIC DCV was enabled. HARICA stated this meant DCV relied solely on corroboration from remote network perspectives, which it said did not satisfy TLS Baseline Requirements section 3.2.2.9. HARICA reported that the issue affected certificates issued through its legacy EJBCA ACME infrastructure between 2025-03-14 and 2026-04-06, and that it developed and deployed a production hotfix on 2026-04-06 and initiated its mass revocation procedure the same day. HARICA also reported that affected certificates were replaced and revoked within required timelines, and that subscribers were notified to replace certificates within 24 hours. In the thread, HARICA provided corrective and preventive action items (including deprecating legacy ACME except for limited profiles, updating due diligence/change-management review procedures, and requesting more detailed vendor documentation) and stated they were completed, with the bug later marked RESOLVED.
- HARICA enabled MPIC on DCV for EJBCA’s ACME service.
- HARICA confirmed the MPIC/DCV issue and deployed a production hotfix while initiating mass revocation.
- HARICA reported that all affected certificates were revoked.
- Mozilla CA Program bug status was updated to RESOLVED.
- HARICA — HARICA submitted a preliminary incident report describing the DCV/MPIC behavior change, the affected certificate population, subscriber notification, and that a full incident report would be submitted by 2026-04-20.
- HARICA — HARICA stated that all affected certificates were revoked before the 24-hour deadline.
- HARICA — HARICA posted the full incident report based on the incident reporting guidelines, including timeline details, impact counts, and that mass revocation and replacement occurred within 24 hours.
- HARICA — HARICA provided an update on completed action items, including deprecating legacy ACME except for limited profiles and updating internal due diligence and vendor documentation requests.
- HARICA — HARICA said it was monitoring the bug for additional questions or concerns before submitting a closure report.
- Community commenter — A commenter requested clarification on HARICA’s decision not to halt issuance, the scope of compliance verification, and mass revocation readiness/testing.
- HARICA — HARICA responded to the questions, stating it would follow end-to-end verification for compliance-relevant workflows and discussing its mass revocation plan testing history and current approach.
- HARICA — HARICA submitted a report closure summary stating the root cause, remediation steps (hotfix, mass revocation, subscriber notifications, ARI configuration), and that action items were completed, requesting closure.
- CCADB representative — CCADB incident reporting account issued a final call for comments before closure.