VISA: Misissuance detected by PKIMetal; bug closed RESOLVED/WONTFIX after incident-reporting non-compliance
This case concerns Visa’s handling of a PKIMetal-reported certificate validity problem under the Visa Public RSA Root CA. Visa acknowledged the report, posted incident reports, and later revised its report to describe a replacement-and-revocation plan for affected certificates. Community commenters continued to press Visa for answers about linting, root cause, revocation, and the completeness of the incident report. CCADB stated that the report remained incomplete and stale, with outstanding questions still needing timely answers. On 2026-07-28, Chrome Root Program staff recommended closing the bug as RESOLVED/WONTFIX because Visa had not met the incident-reporting expectations. The bug is now RESOLVED/WONTFIX.
- The 200-day maximum validity requirement for publicly trusted TLS certificates took effect.
- PKIMetal detected Visa certificates with validity periods exceeding the Baseline Requirements maximum.
- Visa posted preliminary and full incident reports describing the issue and a transition to the Visa TLS Root CA.
- Visa posted a revised incident report and said it was executing a replacement-and-revocation plan.
- CCADB said the report remained incomplete and stale.
- Chrome Root Program staff recommended closing the bug as RESOLVED/WONTFIX.
- CCADB representative — CCADB reported that Visa certificates had validity too long and linked example certificates.
- Visa — Visa acknowledged the report and said it was reviewing the findings.
- Community commenter — A community member asked for a proper incident report and clarification on linting compliance under BR 4.3.1.2.
- Visa — Visa said the certificates exceeded the Baseline Requirements maximum validity and described migration to the Visa TLS Root CA.
- Visa — Visa posted preliminary and full incident reports with timeline, impact counts, and root-cause analysis.
- CCADB representative — CCADB asked whether the certificates were EV, OV, or DV.
- Visa — Visa replied that the certificates were OV.
- Visa — Visa asked whether further clarification or additional corrective actions were needed before closure.
- Community commenter — A community member said key linting and revocation questions remained unanswered and objected to the closure request.
- Visa — Visa created updated incident-report attachments and said it was executing a replacement-and-revocation plan.
- Community commenter — A community member asked for more complete per-certificate details than serial numbers alone.
- Community commenter — A community member said the revised report still left major questions unanswered and criticized the revocation timeline and reporting quality.
- CCADB representative — CCADB said the report remains incomplete and stale, with outstanding community questions still expected to be addressed.
- Google representative — Chrome Root Program staff recommended closing the bug as RESOLVED/WONTFIX because the CA owner had not met incident-reporting expectations.