← Open Access Technology International, Inc. (OATI) cases
Bugzilla #2041774 Ca Certificate Compliance Incident Self Reported Incident Repository Issue Policy Document Issue

OATI compliance incident: AIA CA Issuer field pointed to a PEM-encoded file instead of DER

ASSIGNED Open Access Technology International, Inc. (OATI)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns an OATI compliance incident involving the AIA CA Issuer field in OATI TLS certificates, which pointed to a repository-hosted PEM-encoded file instead of the DER-encoded format required by RFC 5280. OATI said the issue was first identified on 2026-04-29 and remediated by republishing the issuer certificate files in DER format on 2026-05-21. The thread also records OATI’s acknowledgement that it did not file the incident report in the expected CCADB timeline and that its internal procedures lacked encoding verification and incident-response steps. In later updates, OATI reported that automated monitoring/alerting and periodic incident-review work were completed on 2026-06-29. OATI also said it had drafted an updated incident-response policy with 24/7 escalation, and that this remaining action item was still ongoing as of 2026-07-22, with completion anticipated around 2026-07-31.

Model: gpt-5.4-mini Generated: 2026-06-13 21:07 UTC Revised: 2026-07-26 06:01 UTC Confidence: 0.96 14 comments
Chronology
  1. OATI published the Server Issuing CA 2025 issuer certificate file in its repository.
  2. OATI became aware that the AIA CA Issuer pointer referenced a PEM file instead of a DER-encoded certificate.
  3. OATI republished the issuer certificate files in DER format.
  4. OATI completed automated monitoring/alerting for repository file formats and periodic incident-review process work.
Thread Activity
  1. Oati representative — OATI filed a full incident report describing the PEM-encoded AIA CA Issuer file, the remediation, and the timeline.
  2. Community commenter — A community member criticized the timeliness of OATI’s handling and questioned the reporting timeline.
  3. Oati representative — OATI added more root-cause detail, including incomplete internal instructions, no encoding verification process, and no continuous-improvement process.
  4. Oati representative — OATI said it first became aware when the issue was posted on Bugzilla and acknowledged the gap between responses and the solution.
  5. Oati representative — OATI updated action items and then corrected them, including automated monitoring/alerting and incident-response improvements.
  6. Oati representative — OATI said it was still working on the action items and expected some to complete the following week.
  7. Oati representative — OATI reported completion of the monitoring/alerting and incident-review action items, with incident-response process work still ongoing.
  8. Oati representative — OATI said there were no new updates and that it was ahead of schedule on the remaining action item completion date.
  9. Oati representative — OATI said it was still ahead of schedule on the last remaining action item completion date.
Participants
Oati representative Community commenter
Related Bugzilla IDs Mentioned
Similar Local Cases
#2032482 ASSIGNED Ca Certificate Compliance Certificate Misissuance Problem Reporting Failure Audit Finding Opened 2026-04-16 Still Open · 81% similar
OATI: Misissuance detected by PKIMetal
#1967929 RESOLVED Incident Opened 2025-05-22 · Closed 2025-07-17 · 77% similar
KIR: Failed to respond a Certificate Problem Report within 24 hours
#2053948 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Ccadb Disclosure Issue Opened 2026-07-09 Still Open · 72% similar
IdenTrust: Delayed disclosure of Intermediate CA in CCADB
#2052541 ASSIGNED Ca Certificate Compliance Incident Problem Reporting Failure Ccadb Disclosure Issue Opened 2026-07-03 Still Open · 70% similar
NETLOCK: Failure to Respond to a Certificate Problem Report Within 24 Hours
#2056934 UNCONFIRMED Ca Certificate Compliance Incident Ccadb Disclosure Issue Policy Document Issue Opened 2026-07-22 Still Open · 70% similar
Actalis: failure to timely update CP/CPS for AgID SubCAs
#2049179 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Problem Reporting Failure Opened 2026-06-21 Still Open · 69% similar
CFCA: OCSP Service return unauthorized responses
#2048995 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Problem Reporting Failure Opened 2026-06-19 Still Open · 69% similar
eMudhra emSign PKI Services: OCSP Responder Returned "Unauthorized" for Some Pecertificates
#2047579 ASSIGNED Ca Certificate Compliance Audit Finding Policy Document Issue Audit Document Opened 2026-06-15 Still Open · 69% similar
ANF AC: 2026 Audit Report Finding 1 out of 3

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action