← HARICA cases
Bugzilla #2056668 Self Reported Incident Policy Document Issue Incident Opened By Ca Single Ca Owner

HARICA self-reported CP/CPS mismatch for TLS certificates issued without AIA OCSP URI

RESOLVED FIXED HARICA
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

HARICA reported a self-disclosed incident involving Server TLS certificates issued without an AIA OCSP URI while HARICA's CP/CPS versions 4.8 through 4.13 still required that URI. The issue was first raised by the Chrome Root Program team in a comment on bug 2055551, and HARICA confirmed the violation on 2026-07-20. HARICA said it briefly stopped issuance, restored the AIA OCSP URI to the affected TLS certificate profiles, and later updated CP/CPS version 4.14 to make the URI optional. HARICA stated that affected subscribers were notified, replacement certificates were issued where applicable, and revocation of the remaining affected certificates began on 2026-07-25 and was completed eight minutes later. HARICA also updated its change-management procedure so future certificate-profile changes require an explicit CP/CPS compatibility check and approval by both a Compliance Officer and a CA Engineer. The bug was later closed after HARICA posted a closure summary and CCADB issued a final call for comments.

Model: gpt-5.4-mini Generated: 2026-07-26 06:25 UTC Revised: 2026-09-06 06:02 UTC Confidence: 0.98 11 comments
Chronology
  1. HARICA removed the AIA OCSP URI from its production TLS certificate profiles.
  2. Chrome Root Program raised a possible CP/CPS inconsistency about the AIA OCSP URI.
  3. HARICA confirmed the CP/CPS violation and restored the AIA OCSP URI to the affected TLS certificate profiles.
  4. HARICA completed revocation of the remaining affected certificates.
  5. HARICA completed the change-management action item for certificate profile changes.
  6. HARICA posted a closure summary and requested closure of the bug.
  7. The bug status was resolved with FIXED.
Thread Activity
  1. HARICA — HARICA opened a preliminary incident report describing the CP/CPS mismatch, the affected certificate window, and planned replacement and revocation.
  2. HARICA — HARICA posted the full incident report, stating that all affected certificates had been revoked and that issuance had been briefly stopped.
  3. Community commenter — A commenter challenged the incident heuristic and said the report should be self-contained rather than referring to related incidents.
  4. HARICA — HARICA said the heuristic was an approximation, explained that some certificates were intentionally issued with OCSP URIs during pre-agreed windows, and said it was monitoring the bug for further questions or comments.
  5. HARICA — HARICA said the unique action item in this bug was completed on 2026-08-13 and proposed moving future updates to bug 2055551.
  6. HARICA — HARICA posted a closure summary stating that all action items were completed and requesting closure.
  7. CCADB representative — CCADB issued a final call for comments and said the bug would be closed on approximately 2026-08-31.
  8. The bug was marked RESOLVED with FIXED.
Participants
HARICA Community commenter CCADB representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#2017845 RESOLVED Certificate Misissuance Self Reported Incident Problem Reporting Failure Opened 2026-02-19 · Closed 2026-07-28 · 88% similar
HARICA: Incorrect nCAId in PSD2 QCStatement for QWACs
#2029643 RESOLVED Self Reported Incident Revocation Issue Certificate Misissuance Opened 2026-04-06 · Closed 2026-05-22 · 88% similar
HARICA: Incorrect Open MPIC Lambda implementation by EJBCA ACME Service
#2033170 RESOLVED Ca Security Vulnerability Incident Self Reported Incident Revocation Issue Opened 2026-04-18 · Closed 2026-07-20 · 87% similar
DigiCert: Misissued code signing certificates
#2009491 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Repository Issue Opened 2026-01-09 · Closed 2026-02-17 · 86% similar
DigiCert: Several non-functioning AIA URLs
#2011314 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Externally Reported Incident Opened 2026-01-19 · Closed 2026-06-23 · 86% similar
Netlock: unspecifed revocation code (0) in CRL
#2014610 RESOLVED Self Reported Incident Incident Opened 2026-02-05 · Closed 2026-04-11 · 85% similar
IdenTrust: Root OCSP Signer certificate mis-issuance
#2016585 RESOLVED Self Reported Incident Incident Opened 2026-02-12 · Closed 2026-06-15 · 85% similar
IdenTrust: Test Certificates from cross-signed roots not disclosed in CT Logs
#2013395 RESOLVED Self Reported Incident Incident Opened 2026-01-29 · Closed 2026-05-26 · 83% similar
NETLOCK: Missing Related Incidents section in the bug report

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action