CCA India: PKIMetal-detected certificate misissuance in IDRBT CA SPL 2022-1, closed after closure summary
This case concerns SSL/TLS certificates issued under the IDRBT CA SPL 2022-1 hierarchy operated by CCA India that contained non-compliant ASN.1 encoding in the Certificate Policies explicitText field. The issue was disclosed externally through Mozilla Bugzilla and PKIMetal lint findings, and CCA India reported that the affected profile allowed VisibleString or BMPString instead of UTF8String. CCA India said it stopped issuance under the affected profile, corrected and redeployed the profile configuration, and added pre-issuance linting as an issuance-blocking control. It later reported that all 151 affected certificate records had been reconciled against the published CRL, with 145 revoked and 6 expired before revocation. On 2026-07-31 CCA India submitted a closure summary requesting bug closure, and CCADB issued a final call for comments saying the report would be closed around 2026-08-07. The bug is now resolved.
- Non-compliance start date for the affected certificate profile was reported.
- Non-compliance was identified.
- Issuance under the affected certificate profile was stopped.
- The certificate profile configuration was corrected and redeployed.
- The latest CRL referenced in the thread was published.
- CCA India reported that all non-expired affected certificates had been revoked and six had expired before revocation.
- CCA India marked the remediation and replacement action item complete.
- CCA India said all action items had been closed.
- CCA India submitted a closure summary requesting bug closure.
- CCADB representative — The bug was opened with examples showing Certificate Policies explicitText encoded as VisibleString or BMPString and crt.sh trust flags for the affected certificates.
- Community commenter — A community member asked for clarification on linting controls, whether linting was issuance-blocking, and whether additional similar certificates had been identified.
- Government of India, Ministry of Communications & Information Technology, Controller of Certifying Authorities (CCA) — CCA India filed a preliminary incident report describing the explicitText encoding issue and requesting identification of the affected population, root cause, linting controls, and remediation details.
- Government of India, Ministry of Communications & Information Technology, Controller of Certifying Authorities (CCA) — CCA India filed a full incident report stating the root cause, that issuance under the affected profile was stopped, and that 251 certificates were impacted with controlled revocation and replacement planned.
- CCADB representative — CCADB marked the report stale and asked CCA India to address outstanding community questions and set the Next update field.
- Government of India, Ministry of Communications & Information Technology, Controller of Certifying Authorities (CCA) — CCA India provided a status update saying remediation was ongoing and requested the Next update field be set to 21 July 2026.
- CCADB representative — CCADB asked CCA India to continue providing status updates at least every seven days while the incident remained open.
- Government of India, Ministry of Communications & Information Technology, Controller of Certifying Authorities (CCA) — CCA India reported that all non-expired affected certificates had been revoked, six had expired before revocation, and pre-issuance linting had been added to the issuance workflow.
- Government of India, Ministry of Communications & Information Technology, Controller of Certifying Authorities (CCA) — CCA India said it was still working on the action item and would provide the update.
- Government of India, Ministry of Communications & Information Technology, Controller of Certifying Authorities (CCA) — CCA India updated the action-item table to mark the remediation and replacement activity complete.
- Government of India, Ministry of Communications & Information Technology, Controller of Certifying Authorities (CCA) — CCA India said all action items had been closed and that it would submit the closure report by 2026-08-04.
- Government of India, Ministry of Communications & Information Technology, Controller of Certifying Authorities (CCA) — CCA India submitted a closure summary describing the root causes, remediation, and request for closure.
- CCADB representative — CCADB said the affected certificates appear to be OV certificates and issued a final call for comments before expected closure.