← Open Access Technology International, Inc. (OATI) cases
Bugzilla #2032482 Ca Certificate Compliance Incident Certificate Misissuance Problem Reporting Failure Linting Quality Issue

OATI misissuance and missed Certificate Problem Report response

RESOLVED FIXED Open Access Technology International, Inc. (OATI)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns Open Access Technology International, Inc. (OATI) and two related compliance issues: a PKIMetal-detected certificate misissuance in a legacy issuer and a missed response to a Certificate Problem Report. OATI reported that certificates issued from the legacy issuer "webCARES Issuing CA 2021" contained authorityCertIssuer and authorityCertSerialNumber fields that were not permitted. OATI said the impacted certificates were internal TLS certificates, revoked them, removed the fields, and enabled linting on the legacy issuer. The thread also records that a Certificate Problem Report email was sent to spam and OATI did not see or respond to it. OATI later implemented a public certificate problem report contact process, updated its documentation and CPS to reflect that process, and completed its review of spam messages with no additional missed reports found. The bug was resolved with FIXED, and CCADB issued a final call for comments before stating it would be closed around 2026-07-30.

Model: gpt-5.4-mini Generated: 2026-06-13 21:07 UTC Revised: 2026-08-02 07:00 UTC Confidence: 0.98 21 comments
Chronology
  1. Certificate issuance from the legacy issuer webCARES Issuing CA 2021 was enabled and misconfigured to include prohibited authorityCertIssuer and authorityCertSerialNumber fields.
  2. PKIMetal-detected misissuance was reported to OATI and the bug was opened.
  3. OATI revoked the impacted certificates and removed the prohibited fields from the legacy issuer.
  4. OATI completed implementation of a certificate problem report contact process and completed its incident-report review process.
  5. OATI completed its spam-message review with no additional missed Certificate Problem Reports found and finished the documentation and CPS updates for the new process.
Thread Activity
  1. CCADB representative — Reported that OATI certificates contained prohibited authorityCertIssuer and authorityCertSerialNumber fields and linked three affected crt.sh examples.
  2. Oati representative — Said all impacted certificates had been revoked and that the issue was limited to OATI-issued certificates.
  3. Oati representative — Posted an incident report stating the legacy issuer contained the prohibited fields, the scope was three active internal TLS certificates, and the certificates were revoked.
  4. Community commenter — Said prior linting misissuance notifications sent in December 2025 and January 2026 were not responded to and asked why they were not acted upon.
  5. Oati representative — Responded that one report was not answered and the other was likely filtered as spam, and said the email address had been whitelisted.
  6. Google representative — Asked whether OATI would file a separate report for the delayed 24-hour Certificate Problem Report obligations.
  7. Oati representative — Said OATI was reformatting the report, had started reviewing public incident reports, and was planning an online contact form for certificate problem reports.
  8. Oati representative — Posted a full incident report with CCADB ID, timeline, impact, related incidents, root cause analysis, and action items.
  9. Oati representative — Added a root cause factor stating that a certificate problem report email was sent to spam and OATI did not see or respond to it.
  10. Oati representative — Reported progress on automation, incident response improvements, and the new certificate problem report contact form.
  11. Oati representative — Said the certificate problem report contact process was implemented and the incident-report review process was completed.
  12. Oati representative — Said the spam-review process was still ongoing, the contact form implementation was complete but documentation and CPS updates were still being finalized, and the incident-report review process was complete.
  13. Oati representative — Said the spam-message review was completed with no additional missed Certificate Problem Reports found, and that the documentation and CPS updates for the new process were completed.
  14. CCADB representative — Issued a final call for comments or questions and said the incident report would be closed around 2026-07-30 if there were none.
Participants
CCADB representative Oati representative Community commenter Google representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#2041774 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Repository Issue Opened 2026-05-22 · Closed 2026-08-13 · 97% similar
OATI: AIA CA Issuer field pointing to PEM encoded cert
#2047579 RESOLVED Ca Documents Audit Finding Policy Document Issue Information Request Opened 2026-06-15 · Closed 2026-07-27 · 93% similar
ANF AC: 2026 Audit Report Finding 1 out of 3
#2032468 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-04-16 · Closed 2026-08-09 · 88% similar
VISA: Misissuance detected by PKIMetal
#2047952 RESOLVED Ca Certificate Compliance Incident Externally Reported Incident Problem Reporting Failure Opened 2026-06-16 · Closed 2026-08-04 · 86% similar
KIR: OCSP responder does not return status for precertificate
#2055542 RESOLVED Incident Problem Reporting Failure Ccadb Disclosure Issue Opened 2026-07-16 · Closed 2026-08-17 · 80% similar
DigiCert: Delayed response to problem report related to Bug 2055539
#2055539 RESOLVED Problem Reporting Failure Incident Externally Reported Incident Revocation Issue Opened 2026-07-16 · Closed 2026-08-11 · 79% similar
DigiCert: Delayed availability of OCSP responses
#2049179 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Problem Reporting Failure Opened 2026-06-21 · Closed 2026-08-04 · 79% similar
CFCA: OCSP Service return unauthorized responses
#2054464 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Problem Reporting Failure Opened 2026-07-13 · Closed 2026-08-17 · 79% similar
CFCA: Delayed response to CPR-related email related with bug 2049179

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action