OATI misissuance and missed Certificate Problem Report response
This case concerns Open Access Technology International, Inc. (OATI) and two related compliance issues: a PKIMetal-detected certificate misissuance in a legacy issuer and a missed response to a Certificate Problem Report. OATI reported that certificates issued from the legacy issuer "webCARES Issuing CA 2021" contained authorityCertIssuer and authorityCertSerialNumber fields that were not permitted. OATI said the impacted certificates were internal TLS certificates, revoked them, removed the fields, and enabled linting on the legacy issuer. The thread also records that a Certificate Problem Report email was sent to spam and OATI did not see or respond to it. OATI later implemented a public certificate problem report contact process, updated its documentation and CPS to reflect that process, and completed its review of spam messages with no additional missed reports found. The bug is still assigned, and on 2026-07-23 CCADB posted a final call for comments before expected closure around 2026-07-30.
- Certificate issuance from the legacy issuer webCARES Issuing CA 2021 was enabled and misconfigured to include prohibited authorityCertIssuer and authorityCertSerialNumber fields.
- PKIMetal-detected misissuance was reported to OATI and the bug was opened.
- OATI revoked the impacted certificates and removed the prohibited fields from the legacy issuer.
- OATI completed implementation of a certificate problem report contact process and completed its incident-report review process.
- OATI completed its spam-message review with no additional missed Certificate Problem Reports found and finished the documentation and CPS updates for the new process.
- CCADB representative — Reported that OATI certificates contained prohibited authorityCertIssuer and authorityCertSerialNumber fields and linked three affected crt.sh examples.
- Oati representative — Said all impacted certificates had been revoked and that the issue was limited to OATI-issued certificates.
- Oati representative — Posted an incident report stating the legacy issuer contained the prohibited fields, the scope was three active internal TLS certificates, and the certificates were revoked.
- Community commenter — Said prior linting misissuance notifications sent in December 2025 and January 2026 were not responded to and asked why they were not acted upon.
- Oati representative — Responded that one report was not answered and the other was likely filtered as spam, and said the email address had been whitelisted.
- Google representative — Asked whether OATI would file a separate report for the delayed 24-hour Certificate Problem Report obligations.
- Oati representative — Said OATI was reformatting the report, had started reviewing public incident reports, and was planning an online contact form for certificate problem reports.
- Oati representative — Posted a full incident report with CCADB ID, timeline, impact, related incidents, root cause analysis, and action items.
- Oati representative — Added a root cause factor stating that a certificate problem report email was sent to spam and OATI did not see or respond to it.
- Oati representative — Reported progress on automation, incident response improvements, and the new certificate problem report contact form.
- Oati representative — Said the certificate problem report contact process was implemented and the incident-report review process was completed.
- Oati representative — Said the spam-review process was still ongoing, the contact form implementation was complete but documentation and CPS updates were still being finalized, and the incident-report review process was complete.
- Oati representative — Said the spam-message review was completed with no additional missed Certificate Problem Reports found, and that the documentation and CPS updates for the new process were completed.
- CCADB representative — Issued a final call for comments or questions and said the incident report would be closed around 2026-07-30 if there were none.