← Visa cases
Bugzilla #2032468 Ca Certificate Compliance Certificate Misissuance Problem Reporting Failure Audit Finding Remediation Tracking

VISA: Misissuance detected by PKIMetal (TLS certificate validity too long)

ASSIGNED Visa
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns Visa certificates issued under the Visa Public RSA Root CA that exceeded the Baseline Requirements maximum validity for publicly trusted TLS certificates. The issue was first reported by PKIMetal on 2026-04-16, and Visa acknowledged it on 2026-04-22 and began investigating. Visa’s revised incident report says the non-compliance arose during a transition from the Visa Public RSA Root CA to a new Visa TLS Root CA, and Visa acknowledged that treating the public root as private before trust-store removal was incorrect. Visa later stated that issuance had stopped and that it is executing a replacement-and-revocation plan, with target completion dates of 2026-06-30 for TLS server certificates and 2026-07-30 for internal server certificates. The case remains open in Bugzilla, and CCADB says the report is incomplete and stale, with outstanding community questions still needing timely answers. Community comments continue to ask for clearer linting, revocation, and root-cause explanations, but no closure is recorded in the thread.

Model: gpt-5.4-mini Generated: 2026-06-13 20:53 UTC Revised: 2026-06-26 17:36 UTC Confidence: 0.95 17 comments
Chronology
  1. Visa defined a transition strategy to move the Visa Public RSA Root CA from public usage to private use and updated its CP/CPS accordingly.
  2. The 200-day maximum validity requirement for publicly trusted TLS certificates took effect, and Visa issued certificates exceeding that limit under the Visa Public RSA Root CA.
  3. PKIMetal detected and reported that Visa had issued TLS certificates with validity periods exceeding the Baseline Requirements maximum.
  4. Visa publicly acknowledged the incident and said it was reviewing the findings.
  5. Visa posted preliminary and full incident reports describing scope, impact, and remediation via a new Visa TLS Root CA.
  6. Visa reported that the non-compliance ended on this date in the revised report.
  7. Visa posted a revised full incident report and certificate list attachment(s) for TLS server certificates subject to revocation by 2026-06-30.
Thread Activity
  1. CCADB representative — CCADB reported that Visa certificates had validity too long and linked example certificates.
  2. Visa — Visa acknowledged the report and said it was investigating the identified certificates.
  3. Community commenter — A community member asked for a proper incident report and asked Visa to clarify linting compliance under BR 4.3.1.2.
  4. Visa — Visa said the certificates exceeded the Baseline Requirements maximum validity and described migration to the Visa TLS Root CA.
  5. Visa — Visa posted preliminary and full incident reports with timeline, impact counts, and root-cause analysis.
  6. CCADB representative — CCADB asked whether the certificates were EV, OV, or DV.
  7. Visa — Visa replied that the certificates were OV.
  8. Visa — Visa asked whether further clarification or additional corrective actions were needed before closure.
  9. Community commenter — A community member said key linting and revocation questions remained unanswered and objected to the closure request.
  10. Visa — Visa created updated incident-report attachments and said it was executing a replacement-and-revocation plan.
  11. Community commenter — A community member asked for more complete per-certificate details than serial numbers alone.
  12. Community commenter — A community member said the revised report still left major questions unanswered and criticized the revocation timeline and reporting quality.
  13. CCADB representative — CCADB said the report remains incomplete and stale, with outstanding community questions still expected to be addressed.
Participants
CCADB representative Visa Community commenter
Related Bugzilla IDs Mentioned
Similar Local Cases
#2032473 ASSIGNED Ca Certificate Compliance Incident Externally Reported Incident Certificate Misissuance Opened 2026-04-16 Still Open · 88% similar
CCA India: Misissuance detected by PKIMetal
#2037000 ASSIGNED Self Reported Incident Certificate Misissuance Problem Reporting Failure Opened 2026-05-05 Still Open · 80% similar
D-Trust: Missing Pre-Sign Linting for S/MIME Issuing CAs
#2044023 RESOLVED Certificate Misissuance Self Reported Incident Remediation Tracking Opened By Ca Opened 2026-06-01 · Closed 2026-07-02 · 78% similar
Asseco DS / Certum: Cross-Certificates subject encoding discrepancy
#2023458 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2026-03-15 · Closed 2026-06-12 · 78% similar
D-Trust: TLS Precertificates Exceeding the Maximum Validity Period Allowed by the TLS Baseline Requirements
#1890898 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2024-04-11 · Closed 2024-07-28 · 77% similar
Entrust: Failure to revoke OV TLS - CPS typographical (text placement) error
#2056087 ASSIGNED Ca Certificate Compliance Incident Externally Reported Incident Certificate Misissuance Opened 2026-07-19 Still Open · 72% similar
Disig: CP/CPS misstatement regarding Key Usage criticality for TLS certificates
#1836443 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2023-06-02 · Closed 2024-06-30 · 72% similar
GlobalSign: Issuance of test certificate (pre-certificate) for EV SSL/QWAC with no EKU extension
#2055551 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-07-16 Still Open · 71% similar
HARICA: Issuance of Server TLS Certificates with id-kp-clientAuth KeyPurposeID against CP/CPS

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action