← Government of India, Ministry of Communications & Information Technology, Controller of Certifying Authorities (CCA) cases
Bugzilla #2032473 Ca Certificate Compliance Incident Externally Reported Incident Certificate Misissuance Validation Issue

CCA India: PKIMetal-detected certificate misissuance involving Certificate Policies explicitText encoding

ASSIGNED Government of India, Ministry of Communications & Information Technology, Controller of Certifying Authorities (CCA)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns CCA India’s issuance of TLS certificates under the publicly trusted hierarchy IDRBT CA SPL 2022-1 where the Certificate Policies extension explicitText was reported as encoded using VisibleString or BMPString. The issue was first raised externally through Mozilla/CCADB communication and PKIMetal/crt.sh lint findings, with example certificates linked in the thread. CCA India reported that the problem came from certificate profile configuration combined with limitations in validation coverage, and it stopped issuance under the affected profile after confirming the issue. CCA India later said it corrected the certificate profile, completed review of the affected population, and incorporated pre-issuance linting into the issuance workflow. In its 2026-07-06 update, CCA India said all non-expired affected certificates had been revoked and six had expired before revocation. On 2026-07-22, CCA India marked the remediation action item complete, and the bug remains ASSIGNED.

Model: gpt-5.4-mini Generated: 2026-06-13 21:10 UTC Revised: 2026-07-26 06:00 UTC Confidence: 0.97 13 comments
Chronology
  1. Non-compliance start date for the affected certificate profile was reported.
  2. Non-compliance identified date was reported.
  3. Issuance under the affected certificate profile was stopped after confirmation.
  4. Certificate profile configuration was corrected and updated handling was deployed.
  5. The latest CRL referenced in the thread was published.
  6. CCA India reported that all non-expired affected certificates had been revoked and six had expired before revocation.
  7. CCA India marked the remediation action item complete.
Thread Activity
  1. CCADB representative — The bug was opened with examples showing Certificate Policies explicitText encoded as VisibleString or BMPString and crt.sh trust flags for the affected certificates.
  2. Community commenter — A community member asked for clarification on linting controls, whether linting was issuance-blocking, and whether additional similar certificates had been identified.
  3. Government of India, Ministry of Communications & Information Technology, Controller of Certifying Authorities (CCA) — CCA India filed a preliminary incident report describing the explicitText encoding issue and requesting identification of the affected population, root cause, linting controls, and remediation details.
  4. Government of India, Ministry of Communications & Information Technology, Controller of Certifying Authorities (CCA) — CCA India filed a full incident report stating the root cause, that issuance under the affected profile was stopped, and that 251 certificates were impacted with controlled revocation and replacement planned.
  5. CCADB representative — CCADB marked the report stale and asked CCA India to address outstanding community questions and set the Next update field.
  6. Government of India, Ministry of Communications & Information Technology, Controller of Certifying Authorities (CCA) — CCA India provided a status update saying remediation was ongoing and requested the Next update field be set to 21 July 2026.
  7. CCADB representative — CCADB asked CCA India to continue providing status updates at least every seven days while the incident remained open.
  8. Government of India, Ministry of Communications & Information Technology, Controller of Certifying Authorities (CCA) — CCA India reported that all non-expired affected certificates had been revoked, six had expired before revocation, and pre-issuance linting had been added to the issuance workflow.
  9. Government of India, Ministry of Communications & Information Technology, Controller of Certifying Authorities (CCA) — CCA India said it was still working on the action item and would provide the update.
  10. Government of India, Ministry of Communications & Information Technology, Controller of Certifying Authorities (CCA) — CCA India updated the action-item table to mark the remediation and replacement activity complete.
Participants
CCADB representative Community commenter Government of India, Ministry of Communications & Information Technology, Controller of Certifying Authorities (CCA)
Related Bugzilla IDs Mentioned
Similar Local Cases
#2032468 ASSIGNED Ca Certificate Compliance Certificate Misissuance Problem Reporting Failure Audit Finding Opened 2026-04-16 Still Open · 88% similar
VISA: Misissuance detected by PKIMetal
#1970259 RESOLVED Certificate Misissuance Incident Self Reported Incident Opened 2025-06-03 · Closed 2025-08-26 · 78% similar
GoDaddy: Precertificates incorrectly logged to DigiCert SCT Logs
#2023458 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2026-03-15 · Closed 2026-06-12 · 77% similar
D-Trust: TLS Precertificates Exceeding the Maximum Validity Period Allowed by the TLS Baseline Requirements
#1743935 RESOLVED Certificate Misissuance Incident Opened 2021-12-02 · Closed 2023-02-22 · 72% similar
Amazon Trust Services: Misissuance of Subordinate Per CPS
#1502957 RESOLVED Certificate Misissuance Incident Opened 2018-10-29 · Closed 2023-02-22 · 72% similar
Camerfirma: MULTICERT Misissuance and missing audits
#2056087 ASSIGNED Ca Certificate Compliance Incident Externally Reported Incident Certificate Misissuance Opened 2026-07-19 Still Open · 71% similar
Disig: CP/CPS misstatement regarding Key Usage criticality for TLS certificates
#1744518 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-12-06 · Closed 2023-02-22 · 71% similar
GlobalSign: EV certificates with serialNumber Government Entity and businessCategory Private Organization
#1760311 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-03-18 · Closed 2023-02-22 · 71% similar
GlobalSign: OCSP responder certificates with more than 64 characters in CN

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action