← HARICA cases
Bugzilla #2049237 Ca Certificate Compliance Incident Externally Reported Incident Revocation Issue Information Request

HARICA: external report alleging continued issuance and refusal to revoke DV TLS certificates for domains associated with EU-sanctioned entities

RESOLVED INVALID HARICA
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case was opened by an external reporter who alleged that HARICA issued and continued to maintain DV TLS certificates for domains that commenters associated with EU-sanctioned entities, and that HARICA declined to revoke them after receiving multiple Certificate Problem Reports. Additional commenters expanded the scope with more domains, datasets, ticket numbers, and copies of prior correspondence that they said had been sent to HARICA. HARICA stated that all certificates referenced in the bug were issued through its self-service CertManager workflow rather than its pre-validated enterprise ACME workflow, and said that in this self-service DV path identity information is neither required nor verified for certificate issuance. HARICA further said that account registration can contain fake information, that no government ID is submitted at registration time, and that sanctions screening in this workflow occurs only when a customer requests a business invoice. HARICA reiterated that its current interpretation is that revocation is not required absent further legal or regulatory direction, and said it continues to explore such direction. HARICA also said it would improve its public guides to remove ambiguity about account-registration expectations in the self-service DV flow. Mozilla stated earlier in the thread that it had not yet reached any conclusions and later reminded participants to follow Mozilla’s community participation guidelines. The bug is now closed as RESOLVED INVALID.

Model: gpt-5.4 Generated: 2026-06-23 19:11 UTC Revised: 2026-08-02 07:02 UTC Confidence: 0.95 93 comments
Chronology
  1. Reporters said they submitted multiple Certificate Problem Reports to HARICA regarding certificates they associated with sanctioned entities.
  2. Reporter said HARICA had closed reports and declined revocation for cited DV TLS certificates.
  3. HARICA publicly stated that DV certificates only validate domain control and that revocation was not required absent further legal or regulatory direction.
  4. HARICA stated that the certificates in the bug were issued through its self-service CertManager workflow rather than its pre-validated enterprise ACME service.
  5. HARICA said account registration in the self-service DV flow does not require ID submission, may contain fake information, and that it would improve its guides to reduce ambiguity.
  6. HARICA reiterated that its current interpretation is that revocation is not required without further legal or regulatory direction and that it continues to explore such direction.
Thread Activity
  1. Duck representative — Opened the bug alleging HARICA continued issuing and refused to revoke DV TLS certificates for domains associated with sanctioned entities, and quoted HARICA’s CPR response.
  2. Community commenter — Argued that HARICA needed to address the issue and referenced another Bugzilla case as similar context.
  3. Silomails representative — Added a larger list of domains and sanctions references that they said had also been reported to HARICA.
  4. Mozilla representative — Clarified that Mozilla had not reached any conclusions and that the bug was for fact gathering.
  5. HARICA — Said HARICA was monitoring the bug and planned to respond by 2026-07-03.
  6. Duck representative — Added another certificate example and asked that it be included in the investigation.
  7. HARICA — Stated HARICA’s position that DV certificates only validate domain control and that revocation was not required absent further legal or regulatory direction.
  8. Community commenter — Disagreed with HARICA’s position and argued that other CAs had revoked similar certificates after notification.
  9. Community commenter — Submitted a larger dataset and argued that HARICA had a systemic compliance problem affecting many domains.
  10. Duck representative — Submitted another dataset and said HARICA had been repeatedly notified through multiple CPR tickets.
  11. Community commenter — Said HARICA had direct prior notice through an earlier supplemental CPR and attached correspondence.
  12. Duck representative — Listed multiple CPR ticket numbers and said HARICA had closed them with the same response.
  13. Community commenter — Argued from HARICA’s public guides that HARICA might have more applicant information than its earlier comments suggested.
  14. Community commenter — Added references to Ukrainian sanctions-related sources for some of the reported domains.
  15. HARICA — Explained that the reported certificates were issued through HARICA’s self-service CertManager path, not its pre-validated enterprise ACME workflow, and described when sanctions screening occurs.
  16. Duck representative — Said he had escalated the matter to HARICA’s auditor and Greek authorities.
  17. Community commenter — Responded that HARICA’s public guide language suggested stronger identity expectations than HARICA described.
  18. Community commenter — Said HARICA’s legal review had already reached the same conclusion before HARICA’s public comments and attached prior correspondence.
  19. Mozilla representative — Reminded participants to follow Mozilla’s community participation guidelines and said he would review the discussion further.
  20. Silomails representative — Said a GlobalSign certificate previously cited by HARICA had since been revoked.
  21. HARICA — Objected to several comments as violating Bugzilla etiquette and community guidelines.
  22. HARICA — Reiterated that all certificates referenced in the bug were issued through the self-service path and that account registration does not require ID submission.
  23. HARICA — Said HARICA allows applicants to register with fake information and would improve its guides to remove ambiguity.
  24. HARICA — Reaffirmed that HARICA’s current interpretation is that revocation is not required without further legal or regulatory direction and that it continues to explore such direction.
  25. Community commenter — Responded that HARICA’s comments still left unresolved questions about applicant information and payment-related records.
  26. Community commenter — Posted a political comment unrelated to the technical handling of the case.
  27. Community commenter — Argued that sanctions law applies regardless of certificate type and noted that other CAs had revoked similar certificates after notification.
  28. Keigher representative — Questioned how a DV certificate could be legitimately obtained for a domain without being the legal entity behind it.
Participants
Duck representative Community commenter Silomails representative Mozilla representative HARICA Cake representative Keigher representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1942130 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2025-01-16 · Closed 2026-07-28 · 78% similar
HARICA: S/MIME certificate issuance without proper validation
#1918427 RESOLVED Ca Certificate Compliance Incident Closure Request Opened 2024-09-12 · Closed 2024-10-11 · 78% similar
D-Trust: Non-compliance of issued root and intermediate S/MIME certificates
#1705657 RESOLVED Ca Certificate Compliance Revocation Issue Opened 2021-04-16 · Closed 2023-02-22 · 77% similar
KIR S.A.: Many certificates with OCSP Unknown
#1815534 RESOLVED Ca Certificate Compliance Certificate Misissuance Revocation Issue Opened 2023-02-07 · Closed 2024-04-17 · 76% similar
e-commerce monitoring GmbH: SCT in precertificate
#2055551 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-07-16 Still Open · 74% similar
HARICA: Issuance of Server TLS Certificates with id-kp-clientAuth KeyPurposeID against CP/CPS
#2056882 ASSIGNED Externally Reported Incident Certificate Misissuance Closure Request Opened By Subscriber Or Relying Party Opened 2026-07-22 Still Open · 69% similar
D-Trust: EV Subordinate CA missing required cabfOrganizationIdentifier extension
#2056663 ASSIGNED Ca Certificate Compliance Externally Reported Incident Certificate Misissuance Problem Reporting Failure Opened 2026-07-21 Still Open · 69% similar
DigiCert: EVG CA profile compliance
#2047843 RESOLVED Ca Certificate Compliance Problem Reporting Failure Revocation Issue Opened 2026-06-16 · Closed 2026-07-09 · 68% similar
Certigna: Pre-certificates not recognised by the OCSP responder

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action