← Open Access Technology International, Inc. (OATI) cases
Bugzilla #2032482
Certificate Misissuance
OATI: Misissuance detected by PKIMetal
ASSIGNED
Open Access Technology International, Inc. (OATI)
AI Summary
Open Access Technology International, Inc. (OATI) identified a misissuance of TLS certificates from the legacy issuer 'webCARES Issuing CA 2021', which included prohibited fields: authorityCertIssuer and authorityCertSerialNumber. The issue was reported on April 16, 2026, and OATI confirmed that three internal TLS certificates were affected. All impacted certificates were revoked by April 20, 2026, and OATI has since implemented measures to prevent recurrence, including enabling linting and reviewing incident reports from other CAs for continuous improvement.
Chronology
- Certificate issuance from the 2021 issuer was enabled and misconfigured.
- Bugzilla incident report created and investigation began.
- All impacted TLS certificates were revoked.
Participants
incident-reporting@ccadb.org
rootprogram@oati.net
dean.f.reed@protonmail.com
chrome-root-program@google.com
External References
Similar Local Cases
Firmaprofesional: Misissuance of TLS Subordinate CA "AC Firmaprofesional - Secure Web 2024"
TunTrust: SSL OV mis-issuance against CP/CPS (Email attribute)
Actalis: Issuance of certificate using keys previously reported as compromised
Government of Korea: Misissuance detected by PKIMetal
CCA India: Misissuance detected by PKIMetal
VISA: Misissuance detected by PKIMetal
PostSignum: Mis-issued certificate
DigiCert: Misissuance detected by PKIMetal