HARICA preliminary incident report: CP/CPS mismatch for AIA OCSP URI in TLS certificate profiles
HARICA filed a preliminary incident report about a mismatch between its TLS certificate profiles and its CP/CPS language for the AIA OCSP URI. HARICA says the Chrome Root Program team reported a possible inconsistency on 2026-07-17, after HARICA had removed the AIA OCSP URI from its TLS Certificate profiles. HARICA states it failed to update Section 7.1.2.3 of the CP/CPS to reflect that the inclusion is now optional. HARICA says all TLS certificates issued after 2026-03-27 09:31:01 EST and before 2026-07-20 22:53 EEST are affected, and that those certificates will be replaced and revoked as required by the Baseline Requirements. HARICA also said a full incident report would be posted no later than 2026-07-31. The bug remains UNCONFIRMED.
- Chrome Root Program reported a possible CP/CPS inconsistency about AIA OCSP URI in HARICA TLS certificate profiles.
- HARICA removed the AIA OCSP URI from its TLS certificate profiles.
- HARICA added the AIA OCSP URI back to its TLS certificate profiles.
- HARICA — HARICA opened a preliminary incident report describing the CP/CPS mismatch, identifying affected certificates, and saying they will be replaced and revoked.