VISA: Misissuance detected by PKIMetal (TLS certificate validity too long)
This case concerns Visa certificates issued under the Visa Public RSA Root CA that exceeded the Baseline Requirements maximum validity for publicly trusted TLS certificates. The issue was first reported by PKIMetal on 2026-04-16, and Visa acknowledged it on 2026-04-22 and began investigating. Visa’s revised incident report says the non-compliance arose during a transition from the Visa Public RSA Root CA to a new Visa TLS Root CA, and Visa acknowledged that treating the public root as private before trust-store removal was incorrect. Visa later stated that issuance had stopped and that it is executing a replacement-and-revocation plan, with target completion dates of 2026-06-30 for TLS server certificates and 2026-07-30 for internal server certificates. The case remains open in Bugzilla, and CCADB says the report is incomplete and stale, with outstanding community questions still needing timely answers. Community comments continue to ask for clearer linting, revocation, and root-cause explanations, but no closure is recorded in the thread.
- Visa defined a transition strategy to move the Visa Public RSA Root CA from public usage to private use and updated its CP/CPS accordingly.
- The 200-day maximum validity requirement for publicly trusted TLS certificates took effect, and Visa issued certificates exceeding that limit under the Visa Public RSA Root CA.
- PKIMetal detected and reported that Visa had issued TLS certificates with validity periods exceeding the Baseline Requirements maximum.
- Visa publicly acknowledged the incident and said it was reviewing the findings.
- Visa posted preliminary and full incident reports describing scope, impact, and remediation via a new Visa TLS Root CA.
- Visa reported that the non-compliance ended on this date in the revised report.
- Visa posted a revised full incident report and certificate list attachment(s) for TLS server certificates subject to revocation by 2026-06-30.
- CCADB representative — CCADB reported that Visa certificates had validity too long and linked example certificates.
- Visa — Visa acknowledged the report and said it was investigating the identified certificates.
- Community commenter — A community member asked for a proper incident report and asked Visa to clarify linting compliance under BR 4.3.1.2.
- Visa — Visa said the certificates exceeded the Baseline Requirements maximum validity and described migration to the Visa TLS Root CA.
- Visa — Visa posted preliminary and full incident reports with timeline, impact counts, and root-cause analysis.
- CCADB representative — CCADB asked whether the certificates were EV, OV, or DV.
- Visa — Visa replied that the certificates were OV.
- Visa — Visa asked whether further clarification or additional corrective actions were needed before closure.
- Community commenter — A community member said key linting and revocation questions remained unanswered and objected to the closure request.
- Visa — Visa created updated incident-report attachments and said it was executing a replacement-and-revocation plan.
- Community commenter — A community member asked for more complete per-certificate details than serial numbers alone.
- Community commenter — A community member said the revised report still left major questions unanswered and criticized the revocation timeline and reporting quality.
- CCADB representative — CCADB said the report remains incomplete and stale, with outstanding community questions still expected to be addressed.