← HARICA cases
Bugzilla #2029643 Self Reported Incident Revocation Issue Certificate Misissuance

HARICA: Incorrect Open MPIC Lambda implementation by EJBCA ACME Service

RESOLVED FIXED HARICA
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

HARICA reported a compliance incident involving its EJBCA ACME service implementation of MPIC (Multi-Perspective Issuance Corroboration). HARICA said it noticed a preliminary incident report from another CA and then investigated, finding that after MPIC was enabled the CA software relied only on MPIC for DCV and did not execute DCV actions from the Primary Network Perspective as it did before MPIC DCV was enabled. HARICA stated this meant DCV relied solely on corroboration from remote network perspectives, which it said did not satisfy TLS Baseline Requirements section 3.2.2.9. HARICA reported that the issue affected certificates issued through its legacy EJBCA ACME infrastructure between 2025-03-14 and 2026-04-06, and that it developed and deployed a production hotfix on 2026-04-06 and initiated its mass revocation procedure the same day. HARICA also reported that affected certificates were replaced and revoked within required timelines, and that subscribers were notified to replace certificates within 24 hours. In the thread, HARICA provided corrective and preventive action items (including deprecating legacy ACME except for limited profiles, updating due diligence/change-management review procedures, and requesting more detailed vendor documentation) and stated they were completed, with the bug later marked RESOLVED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:16 UTC Revised: 2026-06-16 19:18 UTC Confidence: 0.90 10 comments
Chronology
  1. HARICA enabled MPIC on DCV for EJBCA’s ACME service.
  2. HARICA confirmed the MPIC/DCV issue and deployed a production hotfix while initiating mass revocation.
  3. HARICA reported that all affected certificates were revoked.
  4. Mozilla CA Program bug status was updated to RESOLVED.
Thread Activity
  1. HARICA — HARICA submitted a preliminary incident report describing the DCV/MPIC behavior change, the affected certificate population, subscriber notification, and that a full incident report would be submitted by 2026-04-20.
  2. HARICA — HARICA stated that all affected certificates were revoked before the 24-hour deadline.
  3. HARICA — HARICA posted the full incident report based on the incident reporting guidelines, including timeline details, impact counts, and that mass revocation and replacement occurred within 24 hours.
  4. HARICA — HARICA provided an update on completed action items, including deprecating legacy ACME except for limited profiles and updating internal due diligence and vendor documentation requests.
  5. HARICA — HARICA said it was monitoring the bug for additional questions or concerns before submitting a closure report.
  6. Community commenter — A commenter requested clarification on HARICA’s decision not to halt issuance, the scope of compliance verification, and mass revocation readiness/testing.
  7. HARICA — HARICA responded to the questions, stating it would follow end-to-end verification for compliance-relevant workflows and discussing its mass revocation plan testing history and current approach.
  8. HARICA — HARICA submitted a report closure summary stating the root cause, remediation steps (hotfix, mass revocation, subscriber notifications, ARI configuration), and that action items were completed, requesting closure.
  9. CCADB representative — CCADB incident reporting account issued a final call for comments before closure.
Participants
HARICA Community commenter CCADB representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#2017845 RESOLVED Certificate Misissuance Self Reported Incident Problem Reporting Failure Opened 2026-02-19 · Closed 2026-06-29 · 98% similar
HARICA: Incorrect nCAId in PSD2 QCStatement for QWACs
#1943604 RESOLVED Certificate Misissuance Opened 2025-01-24 · Closed 2025-05-25 · 94% similar
HARICA: TLS Server certificate issuance without proper validation
#2056668 UNCONFIRMED Policy Document Issue Incident Self Reported Incident Certificate Misissuance Opened 2026-07-21 Still Open · 90% similar
HARICA: Issuance of Server TLS Certificates without AIA OCSP URI against CP/CPS
#1535772 RESOLVED Incident Certificate Misissuance Revocation Issue Opened 2019-03-15 · Closed 2023-02-22 · 90% similar
HARICA: wrong characters in NC extension of Technically Constrained Intermediate CA Certificates
#1699796 RESOLVED Self Reported Incident Certificate Misissuance Opened 2021-03-19 · Closed 2023-02-22 · 90% similar
HARICA: Certificates with invalid policy tree
#2029230 RESOLVED Self Reported Incident Revocation Issue Opened 2026-04-03 · Closed 2026-05-28 · 89% similar
SSL.com: Incorrect Open MPIC Lambda implementation by EJBCA ACME Service
#1535509 RESOLVED Incident Certificate Misissuance Revocation Issue Opened 2019-03-15 · Closed 2023-02-22 · 89% similar
HARICA: Insufficient serial number entropy
#1597135 RESOLVED Certificate Misissuance Revocation Issue Incident Opened 2019-11-17 · Closed 2023-02-22 · 89% similar
HARICA: 3 EV TLS Certificates without L or ST

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action