OATI compliance incident: AIA CA Issuer field pointed to a PEM-encoded file instead of DER
This case concerns an OATI compliance incident involving the AIA CA Issuer field in OATI TLS certificates, which pointed to a repository-hosted PEM-encoded file instead of the DER-encoded format required by RFC 5280. OATI said the issue was first identified on 2026-04-29 and remediated by republishing the issuer certificate files in DER format on 2026-05-21. The thread also records OATI’s acknowledgement that it did not file the incident report in the expected CCADB timeline and that its internal procedures lacked encoding verification and incident-response steps. In later updates, OATI reported that automated monitoring/alerting and periodic incident-review work were completed on 2026-06-29. OATI also said it had drafted an updated incident-response policy with 24/7 escalation, and that this remaining action item was still ongoing as of 2026-07-22, with completion anticipated around 2026-07-31.
- OATI published the Server Issuing CA 2025 issuer certificate file in its repository.
- OATI became aware that the AIA CA Issuer pointer referenced a PEM file instead of a DER-encoded certificate.
- OATI republished the issuer certificate files in DER format.
- OATI completed automated monitoring/alerting for repository file formats and periodic incident-review process work.
- Oati representative — OATI filed a full incident report describing the PEM-encoded AIA CA Issuer file, the remediation, and the timeline.
- Community commenter — A community member criticized the timeliness of OATI’s handling and questioned the reporting timeline.
- Oati representative — OATI added more root-cause detail, including incomplete internal instructions, no encoding verification process, and no continuous-improvement process.
- Oati representative — OATI said it first became aware when the issue was posted on Bugzilla and acknowledged the gap between responses and the solution.
- Oati representative — OATI updated action items and then corrected them, including automated monitoring/alerting and incident-response improvements.
- Oati representative — OATI said it was still working on the action items and expected some to complete the following week.
- Oati representative — OATI reported completion of the monitoring/alerting and incident-review action items, with incident-response process work still ongoing.
- Oati representative — OATI said there were no new updates and that it was ahead of schedule on the remaining action item completion date.
- Oati representative — OATI said it was still ahead of schedule on the last remaining action item completion date.