CCA India: PKIMetal-detected certificate misissuance involving Certificate Policies explicitText encoding
This case concerns CCA India’s issuance of TLS certificates under the publicly trusted hierarchy IDRBT CA SPL 2022-1 where the Certificate Policies extension explicitText was reported as encoded using VisibleString or BMPString. The issue was first raised externally through Mozilla/CCADB communication and PKIMetal/crt.sh lint findings, with example certificates linked in the thread. CCA India reported that the problem came from certificate profile configuration combined with limitations in validation coverage, and it stopped issuance under the affected profile after confirming the issue. CCA India later said it corrected the certificate profile, completed review of the affected population, and incorporated pre-issuance linting into the issuance workflow. In its 2026-07-06 update, CCA India said all non-expired affected certificates had been revoked and six had expired before revocation. On 2026-07-22, CCA India marked the remediation action item complete, and the bug remains ASSIGNED.
- Non-compliance start date for the affected certificate profile was reported.
- Non-compliance identified date was reported.
- Issuance under the affected certificate profile was stopped after confirmation.
- Certificate profile configuration was corrected and updated handling was deployed.
- The latest CRL referenced in the thread was published.
- CCA India reported that all non-expired affected certificates had been revoked and six had expired before revocation.
- CCA India marked the remediation action item complete.
- CCADB representative — The bug was opened with examples showing Certificate Policies explicitText encoded as VisibleString or BMPString and crt.sh trust flags for the affected certificates.
- Community commenter — A community member asked for clarification on linting controls, whether linting was issuance-blocking, and whether additional similar certificates had been identified.
- Government of India, Ministry of Communications & Information Technology, Controller of Certifying Authorities (CCA) — CCA India filed a preliminary incident report describing the explicitText encoding issue and requesting identification of the affected population, root cause, linting controls, and remediation details.
- Government of India, Ministry of Communications & Information Technology, Controller of Certifying Authorities (CCA) — CCA India filed a full incident report stating the root cause, that issuance under the affected profile was stopped, and that 251 certificates were impacted with controlled revocation and replacement planned.
- CCADB representative — CCADB marked the report stale and asked CCA India to address outstanding community questions and set the Next update field.
- Government of India, Ministry of Communications & Information Technology, Controller of Certifying Authorities (CCA) — CCA India provided a status update saying remediation was ongoing and requested the Next update field be set to 21 July 2026.
- CCADB representative — CCADB asked CCA India to continue providing status updates at least every seven days while the incident remained open.
- Government of India, Ministry of Communications & Information Technology, Controller of Certifying Authorities (CCA) — CCA India reported that all non-expired affected certificates had been revoked, six had expired before revocation, and pre-issuance linting had been added to the issuance workflow.
- Government of India, Ministry of Communications & Information Technology, Controller of Certifying Authorities (CCA) — CCA India said it was still working on the action item and would provide the update.
- Government of India, Ministry of Communications & Information Technology, Controller of Certifying Authorities (CCA) — CCA India updated the action-item table to mark the remediation and replacement activity complete.