← Open Access Technology International, Inc. (OATI) cases
Bugzilla #2032482 Ca Certificate Compliance Certificate Misissuance Problem Reporting Failure Audit Finding Cp Cps Document

OATI misissuance and missed Certificate Problem Report response

ASSIGNED Open Access Technology International, Inc. (OATI)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns Open Access Technology International, Inc. (OATI) and two related compliance issues: a PKIMetal-detected certificate misissuance in a legacy issuer and a missed response to a Certificate Problem Report. OATI reported that certificates issued from the legacy issuer "webCARES Issuing CA 2021" contained authorityCertIssuer and authorityCertSerialNumber fields that were not permitted. OATI said the impacted certificates were internal TLS certificates, revoked them, removed the fields, and enabled linting on the legacy issuer. The thread also records that a Certificate Problem Report email was sent to spam and OATI did not see or respond to it. OATI later implemented a public certificate problem report contact process, updated its documentation and CPS to reflect that process, and completed its review of spam messages with no additional missed reports found. The bug is still assigned, and on 2026-07-23 CCADB posted a final call for comments before expected closure around 2026-07-30.

Model: gpt-5.4-mini Generated: 2026-06-13 21:07 UTC Revised: 2026-07-26 06:00 UTC Confidence: 0.98 21 comments
Chronology
  1. Certificate issuance from the legacy issuer webCARES Issuing CA 2021 was enabled and misconfigured to include prohibited authorityCertIssuer and authorityCertSerialNumber fields.
  2. PKIMetal-detected misissuance was reported to OATI and the bug was opened.
  3. OATI revoked the impacted certificates and removed the prohibited fields from the legacy issuer.
  4. OATI completed implementation of a certificate problem report contact process and completed its incident-report review process.
  5. OATI completed its spam-message review with no additional missed Certificate Problem Reports found and finished the documentation and CPS updates for the new process.
Thread Activity
  1. CCADB representative — Reported that OATI certificates contained prohibited authorityCertIssuer and authorityCertSerialNumber fields and linked three affected crt.sh examples.
  2. Oati representative — Said all impacted certificates had been revoked and that the issue was limited to OATI-issued certificates.
  3. Oati representative — Posted an incident report stating the legacy issuer contained the prohibited fields, the scope was three active internal TLS certificates, and the certificates were revoked.
  4. Community commenter — Said prior linting misissuance notifications sent in December 2025 and January 2026 were not responded to and asked why they were not acted upon.
  5. Oati representative — Responded that one report was not answered and the other was likely filtered as spam, and said the email address had been whitelisted.
  6. Google representative — Asked whether OATI would file a separate report for the delayed 24-hour Certificate Problem Report obligations.
  7. Oati representative — Said OATI was reformatting the report, had started reviewing public incident reports, and was planning an online contact form for certificate problem reports.
  8. Oati representative — Posted a full incident report with CCADB ID, timeline, impact, related incidents, root cause analysis, and action items.
  9. Oati representative — Added a root cause factor stating that a certificate problem report email was sent to spam and OATI did not see or respond to it.
  10. Oati representative — Reported progress on automation, incident response improvements, and the new certificate problem report contact form.
  11. Oati representative — Said the certificate problem report contact process was implemented and the incident-report review process was completed.
  12. Oati representative — Said the spam-review process was still ongoing, the contact form implementation was complete but documentation and CPS updates were still being finalized, and the incident-report review process was complete.
  13. Oati representative — Said the spam-message review was completed with no additional missed Certificate Problem Reports found, and that the documentation and CPS updates for the new process were completed.
  14. CCADB representative — Issued a final call for comments or questions and said the incident report would be closed around 2026-07-30 if there were none.
Participants
CCADB representative Oati representative Community commenter Google representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#2047579 ASSIGNED Ca Certificate Compliance Audit Finding Policy Document Issue Audit Document Opened 2026-06-15 Still Open · 94% similar
ANF AC: 2026 Audit Report Finding 1 out of 3
#2041774 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Repository Issue Opened 2026-05-22 Still Open · 81% similar
OATI: AIA CA Issuer field pointing to PEM encoded cert
#2048995 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Problem Reporting Failure Opened 2026-06-19 Still Open · 77% similar
eMudhra emSign PKI Services: OCSP Responder Returned "Unauthorized" for Some Pecertificates
#2053948 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Ccadb Disclosure Issue Opened 2026-07-09 Still Open · 71% similar
IdenTrust: Delayed disclosure of Intermediate CA in CCADB
#2054464 ASSIGNED Incident Problem Reporting Failure Remediation Tracking Opened By Ca Opened 2026-07-13 Still Open · 71% similar
CFCA: Delayed response to CPR-related email related with bug 2049179
#2052541 ASSIGNED Ca Certificate Compliance Incident Problem Reporting Failure Ccadb Disclosure Issue Opened 2026-07-03 Still Open · 69% similar
NETLOCK: Failure to Respond to a Certificate Problem Report Within 24 Hours
#2056934 UNCONFIRMED Ca Certificate Compliance Incident Ccadb Disclosure Issue Policy Document Issue Opened 2026-07-22 Still Open · 69% similar
Actalis: failure to timely update CP/CPS for AgID SubCAs
#2049179 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Problem Reporting Failure Opened 2026-06-21 Still Open · 69% similar
CFCA: OCSP Service return unauthorized responses

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action