← HARICA cases
Bugzilla #2055551 Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Problem Reporting Failure

HARICA issued Server TLS certificates with clientAuth EKU contrary to its CP/CPS, then corrected the profiles and CP/CPS

ASSIGNED HARICA
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

HARICA reported that it issued Server TLS certificates containing the `id-kp-clientAuth` KeyPurposeID after the removal deadline stated in its own CP/CPS. The thread says the mismatch arose because HARICA’s CP/CPS still reflected an outdated 2026-06-15 cutoff, while Chrome’s Root Store Policy had moved the applicable deadline to 2027-03-15. HARICA said it halted issuance, updated the affected TLS certificate profiles, and later published a corrected CP/CPS. The incident was first reported by a third party, and HARICA later posted a full incident report with the timeline and impact details. The bug remains assigned to HARICA, and HARICA said it is monitoring the bug for further questions while requesting that the next update be deferred until 2026-09-18.

Model: gpt-5.4-mini Generated: 2026-07-16 19:49 UTC Revised: 2026-08-16 06:02 UTC Confidence: 0.97 15 comments
Chronology
  1. HARICA updated CP/CPS v4.9 to incorporate the then-current deadline for removing `id-kp-clientAuth` from TLS certificates.
  2. HARICA’s CP/CPS cutoff for allowing `id-kp-clientAuth` in TLS certificates took effect.
  3. HARICA received a report about the inconsistency between its CP/CPS and actual TLS certificates.
  4. HARICA stopped issuance and updated the TLS certificate profiles.
  5. HARICA published CP/CPS v4.13 with corrected language for the `clientAuth` EKU.
  6. HARICA posted the full incident report.
Thread Activity
  1. HARICA — HARICA filed a preliminary incident report saying it had continued issuing TLS certificates with `id-kp-clientAuth` after its CP/CPS cutoff and would replace and revoke affected certificates within 5 days.
  2. Google representative — Chrome Root Program asked HARICA to answer detailed questions about the controls that should have prevented or detected the misissuance sooner.
  3. HARICA — HARICA acknowledged the issue, said it had confirmed the CP/CPS language problem, halted issuance, and said a bug would be registered within 24 hours.
  4. Molgen representative — A Mozilla participant reported that the HARICA-GEANT-TLS-R1 CRL showed at least one affected certificate as revoked.
  5. HARICA — HARICA said the draft incident report sections on summary, impact, timeline, related incidents, and appendix were complete, while root cause analysis, lessons learned, and action items were still under analysis.
  6. HARICA — HARICA said it needed one more day to post the final root cause analysis, lessons learned, and action items, and noted the report was being aligned with bug 2056668.
  7. HARICA — HARICA posted the full incident report, including the updated timeline and the explanation that the non-compliance ended when the TLS profiles were corrected.
  8. HARICA — HARICA clarified that the timeline wording about enabling clientAuth EKU was a typographical error and that the profiles were updated to remove the TLS client auth EKU.
  9. HARICA — HARICA said it had no new updates and requested deferring the next update until 2026-09-18.
Participants
HARICA Google representative Molgen representative Community commenter
Related Bugzilla IDs Mentioned
Similar Local Cases
#2056668 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Policy Document Issue Opened 2026-07-21 Still Open · 79% similar
HARICA: Issuance of Server TLS Certificates without AIA OCSP URI against CP/CPS
#2056087 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-07-19 Still Open · 79% similar
Disig: CP/CPS misstatement regarding Key Usage criticality for TLS certificates
#1890898 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2024-04-11 · Closed 2024-07-28 · 77% similar
Entrust: Failure to revoke OV TLS - CPS typographical (text placement) error
#2032473 RESOLVED Ca Certificate Compliance Incident Externally Reported Incident Certificate Misissuance Opened 2026-04-16 · Closed 2026-08-08 · 77% similar
CCA India: Misissuance detected by PKIMetal
#2056989 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-07-22 Still Open · 77% similar
FNMT: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy
#2049237 RESOLVED Ca Certificate Compliance Incident Externally Reported Incident Revocation Issue Opened 2026-06-22 · Closed 2026-07-29 · 74% similar
HARICA: Continued issuance and refusal to revoke TLS certificates for EU-sanctioned blocked entities (Sberbank, VTB, KAMAZ, ANO Dialog)
#1465600 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2018-05-30 · Closed 2023-02-22 · 71% similar
DigiCert: Invalid Country Code Issuance
#2044023 RESOLVED Certificate Misissuance Self Reported Incident Remediation Tracking Opened By Ca Opened 2026-06-01 · Closed 2026-07-02 · 71% similar
Asseco DS / Certum: Cross-Certificates subject encoding discrepancy

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action