HARICA issued Server TLS certificates with clientAuth EKU contrary to its CP/CPS, then corrected the profiles and CP/CPS
HARICA reported that it issued Server TLS certificates containing the `id-kp-clientAuth` KeyPurposeID after the removal deadline stated in its own CP/CPS. The thread says the mismatch arose because HARICA’s CP/CPS still reflected an outdated 2026-06-15 cutoff, while Chrome’s Root Store Policy had moved the applicable deadline to 2027-03-15. HARICA said it halted issuance, updated the affected TLS certificate profiles, and later published a corrected CP/CPS. The incident was first reported by a third party, and HARICA later posted a full incident report with the timeline and impact details. The bug remains assigned to HARICA, and HARICA said it is monitoring the bug for further questions while requesting that the next update be deferred until 2026-09-18.
- HARICA updated CP/CPS v4.9 to incorporate the then-current deadline for removing `id-kp-clientAuth` from TLS certificates.
- HARICA’s CP/CPS cutoff for allowing `id-kp-clientAuth` in TLS certificates took effect.
- HARICA received a report about the inconsistency between its CP/CPS and actual TLS certificates.
- HARICA stopped issuance and updated the TLS certificate profiles.
- HARICA published CP/CPS v4.13 with corrected language for the `clientAuth` EKU.
- HARICA posted the full incident report.
- HARICA — HARICA filed a preliminary incident report saying it had continued issuing TLS certificates with `id-kp-clientAuth` after its CP/CPS cutoff and would replace and revoke affected certificates within 5 days.
- Google representative — Chrome Root Program asked HARICA to answer detailed questions about the controls that should have prevented or detected the misissuance sooner.
- HARICA — HARICA acknowledged the issue, said it had confirmed the CP/CPS language problem, halted issuance, and said a bug would be registered within 24 hours.
- Molgen representative — A Mozilla participant reported that the HARICA-GEANT-TLS-R1 CRL showed at least one affected certificate as revoked.
- HARICA — HARICA said the draft incident report sections on summary, impact, timeline, related incidents, and appendix were complete, while root cause analysis, lessons learned, and action items were still under analysis.
- HARICA — HARICA said it needed one more day to post the final root cause analysis, lessons learned, and action items, and noted the report was being aligned with bug 2056668.
- HARICA — HARICA posted the full incident report, including the updated timeline and the explanation that the non-compliance ended when the TLS profiles were corrected.
- HARICA — HARICA clarified that the timeline wording about enabling clientAuth EKU was a typographical error and that the profiles were updated to remove the TLS client auth EKU.
- HARICA — HARICA said it had no new updates and requested deferring the next update until 2026-09-18.