← Government of India, Ministry of Communications & Information Technology, Controller of Certifying Authorities (CCA) cases
Bugzilla #2032473 Ca Certificate Compliance Incident Externally Reported Incident Certificate Misissuance Validation Issue

CCA India: PKIMetal-detected certificate misissuance in IDRBT CA SPL 2022-1, closed after closure summary

RESOLVED FIXED Government of India, Ministry of Communications & Information Technology, Controller of Certifying Authorities (CCA)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns SSL/TLS certificates issued under the IDRBT CA SPL 2022-1 hierarchy operated by CCA India that contained non-compliant ASN.1 encoding in the Certificate Policies explicitText field. The issue was disclosed externally through Mozilla Bugzilla and PKIMetal lint findings, and CCA India reported that the affected profile allowed VisibleString or BMPString instead of UTF8String. CCA India said it stopped issuance under the affected profile, corrected and redeployed the profile configuration, and added pre-issuance linting as an issuance-blocking control. It later reported that all 151 affected certificate records had been reconciled against the published CRL, with 145 revoked and 6 expired before revocation. On 2026-07-31 CCA India submitted a closure summary requesting bug closure, and CCADB issued a final call for comments saying the report would be closed around 2026-08-07. The bug is now resolved.

Model: gpt-5.4-mini Generated: 2026-06-13 21:10 UTC Revised: 2026-08-09 06:00 UTC Confidence: 0.98 16 comments
Chronology
  1. Non-compliance start date for the affected certificate profile was reported.
  2. Non-compliance was identified.
  3. Issuance under the affected certificate profile was stopped.
  4. The certificate profile configuration was corrected and redeployed.
  5. The latest CRL referenced in the thread was published.
  6. CCA India reported that all non-expired affected certificates had been revoked and six had expired before revocation.
  7. CCA India marked the remediation and replacement action item complete.
  8. CCA India said all action items had been closed.
  9. CCA India submitted a closure summary requesting bug closure.
Thread Activity
  1. CCADB representative — The bug was opened with examples showing Certificate Policies explicitText encoded as VisibleString or BMPString and crt.sh trust flags for the affected certificates.
  2. Community commenter — A community member asked for clarification on linting controls, whether linting was issuance-blocking, and whether additional similar certificates had been identified.
  3. Government of India, Ministry of Communications & Information Technology, Controller of Certifying Authorities (CCA) — CCA India filed a preliminary incident report describing the explicitText encoding issue and requesting identification of the affected population, root cause, linting controls, and remediation details.
  4. Government of India, Ministry of Communications & Information Technology, Controller of Certifying Authorities (CCA) — CCA India filed a full incident report stating the root cause, that issuance under the affected profile was stopped, and that 251 certificates were impacted with controlled revocation and replacement planned.
  5. CCADB representative — CCADB marked the report stale and asked CCA India to address outstanding community questions and set the Next update field.
  6. Government of India, Ministry of Communications & Information Technology, Controller of Certifying Authorities (CCA) — CCA India provided a status update saying remediation was ongoing and requested the Next update field be set to 21 July 2026.
  7. CCADB representative — CCADB asked CCA India to continue providing status updates at least every seven days while the incident remained open.
  8. Government of India, Ministry of Communications & Information Technology, Controller of Certifying Authorities (CCA) — CCA India reported that all non-expired affected certificates had been revoked, six had expired before revocation, and pre-issuance linting had been added to the issuance workflow.
  9. Government of India, Ministry of Communications & Information Technology, Controller of Certifying Authorities (CCA) — CCA India said it was still working on the action item and would provide the update.
  10. Government of India, Ministry of Communications & Information Technology, Controller of Certifying Authorities (CCA) — CCA India updated the action-item table to mark the remediation and replacement activity complete.
  11. Government of India, Ministry of Communications & Information Technology, Controller of Certifying Authorities (CCA) — CCA India said all action items had been closed and that it would submit the closure report by 2026-08-04.
  12. Government of India, Ministry of Communications & Information Technology, Controller of Certifying Authorities (CCA) — CCA India submitted a closure summary describing the root causes, remediation, and request for closure.
  13. CCADB representative — CCADB said the affected certificates appear to be OV certificates and issued a final call for comments before expected closure.
Participants
CCADB representative Community commenter Government of India, Ministry of Communications & Information Technology, Controller of Certifying Authorities (CCA)
Related Bugzilla IDs Mentioned
Similar Local Cases
#2056087 ASSIGNED Ca Certificate Compliance Incident Certificate Misissuance Delayed Revocation Opened 2026-07-19 Still Open · 79% similar
Disig: CP/CPS misstatement regarding Key Usage criticality for TLS certificates
#2023458 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2026-03-15 · Closed 2026-07-31 · 79% similar
D-Trust: TLS Precertificates Exceeding the Maximum Validity Period Allowed by the TLS Baseline Requirements
#2056989 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-07-22 Still Open · 77% similar
FNMT: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy
#1890898 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2024-04-11 · Closed 2024-07-28 · 77% similar
Entrust: Failure to revoke OV TLS - CPS typographical (text placement) error
#2055551 ASSIGNED Certificate Misissuance Self Reported Incident Externally Reported Incident Policy Document Issue Opened 2026-07-16 Still Open · 77% similar
HARICA: Issuance of Server TLS Certificates with id-kp-clientAuth KeyPurposeID against CP/CPS
#2032468 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-04-16 · Closed 2026-08-09 · 76% similar
VISA: Misissuance detected by PKIMetal
#1970259 RESOLVED Certificate Misissuance Incident Self Reported Incident Opened 2025-06-03 · Closed 2025-08-26 · 76% similar
GoDaddy: Precertificates incorrectly logged to DigiCert SCT Logs
#1760311 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-03-18 · Closed 2023-02-22 · 72% similar
GlobalSign: OCSP responder certificates with more than 64 characters in CN

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action