← Government of India, Ministry of Communications & Information Technology, Controller of Certifying Authorities (CCA) cases
Bugzilla #2032473 Certificate Misissuance

CCA India: Misissuance detected by PKIMetal

ASSIGNED Government of India, Ministry of Communications & Information Technology, Controller of Certifying Authorities (CCA)
AI Summary

The CCA India has been notified of a misissuance incident involving SSL/TLS certificates issued under the CCA SSL Root CA hierarchy. The issue pertains to the encoding of the explicitText field in the Certificate Policies extension, which was incorrectly encoded using VisibleString or BMPString. A total of 251 certificates were identified as affected, with 151 still valid. The incident was disclosed through Mozilla Bugzilla and related PKIMetal findings. Remediation efforts are underway, including stopping issuance under the affected profile and planning controlled revocation of the impacted certificates to minimize operational disruption.

Model: gpt-4o-mini Generated: 2026-06-13 21:10 UTC Confidence: 0.90
Chronology
  1. Mozilla Bugzilla Bug #2032473 opened
  2. PKIMetal/crt.sh lint findings escalated
  3. Detailed incident response requested by Mozilla Root Program
  4. Issuance under affected certificate profile stopped
  5. Affected certificate population identified
  6. Certificate profile configuration corrected
Participants
incident-reporting@ccadb.org ram@cca.gov.in
Related Bugzilla IDs Mentioned
Similar Local Cases
#2032478 ASSIGNED Certificate Misissuance Opened 2026-04-16 Still Open · 49% similar
Government of Korea: Misissuance detected by PKIMetal
#2032468 ASSIGNED Certificate Misissuance Opened 2026-04-16 Still Open · 49% similar
VISA: Misissuance detected by PKIMetal
#2032482 ASSIGNED Certificate Misissuance Opened 2026-04-16 Still Open · 49% similar
OATI: Misissuance detected by PKIMetal
#1981680 RESOLVED Certificate Misissuance Opened 2025-08-07 · Closed 2025-09-26 · 49% similar
TunTrust: SSL OV mis-issuance against CP/CPS (Email attribute)
#2032485 RESOLVED Certificate Misissuance Opened 2026-04-16 · Closed 2026-05-04 · 48% similar
DigiCert: Misissuance detected by PKIMetal
#2032476 RESOLVED Certificate Misissuance Opened 2026-04-16 · Closed 2026-05-07 · 46% similar
Microsoft PKI Services: Misissuance detected by PKIMetal
#2016722 RESOLVED Certificate Misissuance Opened 2026-02-13 · Closed 2026-03-17 · 46% similar
PostSignum: Mis-issued certificate
#2032479 RESOLVED Certificate Misissuance Opened 2026-04-16 · Closed 2026-05-13 · 46% similar
Certisign: Misissuance detected by PKIMetal

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action