← Visa cases
Bugzilla #2032468 Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Audit Finding

VISA: Misissuance detected by PKIMetal; bug closed RESOLVED/WONTFIX after incident-reporting non-compliance

RESOLVED WONTFIX Visa
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns Visa’s handling of a PKIMetal-reported certificate validity problem under the Visa Public RSA Root CA. Visa acknowledged the report, posted incident reports, and later revised its report to describe a replacement-and-revocation plan for affected certificates. Community commenters continued to press Visa for answers about linting, root cause, revocation, and the completeness of the incident report. CCADB stated that the report remained incomplete and stale, with outstanding questions still needing timely answers. On 2026-07-28, Chrome Root Program staff recommended closing the bug as RESOLVED/WONTFIX because Visa had not met the incident-reporting expectations. The bug is now RESOLVED/WONTFIX.

Model: gpt-5.4-mini Generated: 2026-06-13 20:53 UTC Revised: 2026-08-16 06:00 UTC Confidence: 0.93 18 comments
Chronology
  1. The 200-day maximum validity requirement for publicly trusted TLS certificates took effect.
  2. PKIMetal detected Visa certificates with validity periods exceeding the Baseline Requirements maximum.
  3. Visa posted preliminary and full incident reports describing the issue and a transition to the Visa TLS Root CA.
  4. Visa posted a revised incident report and said it was executing a replacement-and-revocation plan.
  5. CCADB said the report remained incomplete and stale.
  6. Chrome Root Program staff recommended closing the bug as RESOLVED/WONTFIX.
Thread Activity
  1. CCADB representative — CCADB reported that Visa certificates had validity too long and linked example certificates.
  2. Visa — Visa acknowledged the report and said it was reviewing the findings.
  3. Community commenter — A community member asked for a proper incident report and clarification on linting compliance under BR 4.3.1.2.
  4. Visa — Visa said the certificates exceeded the Baseline Requirements maximum validity and described migration to the Visa TLS Root CA.
  5. Visa — Visa posted preliminary and full incident reports with timeline, impact counts, and root-cause analysis.
  6. CCADB representative — CCADB asked whether the certificates were EV, OV, or DV.
  7. Visa — Visa replied that the certificates were OV.
  8. Visa — Visa asked whether further clarification or additional corrective actions were needed before closure.
  9. Community commenter — A community member said key linting and revocation questions remained unanswered and objected to the closure request.
  10. Visa — Visa created updated incident-report attachments and said it was executing a replacement-and-revocation plan.
  11. Community commenter — A community member asked for more complete per-certificate details than serial numbers alone.
  12. Community commenter — A community member said the revised report still left major questions unanswered and criticized the revocation timeline and reporting quality.
  13. CCADB representative — CCADB said the report remains incomplete and stale, with outstanding community questions still expected to be addressed.
  14. Google representative — Chrome Root Program staff recommended closing the bug as RESOLVED/WONTFIX because the CA owner had not met incident-reporting expectations.
Participants
CCADB representative Visa Community commenter Google representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#2032482 RESOLVED Ca Certificate Compliance Incident Certificate Misissuance Problem Reporting Failure Opened 2026-04-16 · Closed 2026-07-30 · 88% similar
OATI: Misissuance detected by PKIMetal
#2041774 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Repository Issue Opened 2026-05-22 · Closed 2026-08-13 · 86% similar
OATI: AIA CA Issuer field pointing to PEM encoded cert
#2055542 RESOLVED Incident Problem Reporting Failure Ccadb Disclosure Issue Opened 2026-07-16 · Closed 2026-08-17 · 78% similar
DigiCert: Delayed response to problem report related to Bug 2055539
#2047952 RESOLVED Ca Certificate Compliance Incident Externally Reported Incident Problem Reporting Failure Opened 2026-06-16 · Closed 2026-08-04 · 78% similar
KIR: OCSP responder does not return status for precertificate
#2048995 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Problem Reporting Failure Opened 2026-06-19 · Closed 2026-07-30 · 78% similar
eMudhra emSign PKI Services: OCSP Responder Returned "Unauthorized" for Some Pecertificates
#2054464 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Problem Reporting Failure Opened 2026-07-13 · Closed 2026-08-17 · 77% similar
CFCA: Delayed response to CPR-related email related with bug 2049179
#2052541 ASSIGNED Problem Reporting Failure Incident Externally Reported Incident Opened By Ca Opened 2026-07-03 Still Open · 77% similar
NETLOCK: Failure to Respond to a Certificate Problem Report Within 24 Hours
#2049179 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Problem Reporting Failure Opened 2026-06-21 · Closed 2026-08-04 · 77% similar
CFCA: OCSP Service return unauthorized responses

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action