HARICA self-reported CP/CPS mismatch for TLS certificates issued without AIA OCSP URI
HARICA reported a self-disclosed incident involving Server TLS certificates issued without an AIA OCSP URI while HARICA's CP/CPS versions 4.8 through 4.13 still required that URI. The issue was first raised by the Chrome Root Program team in a comment on bug 2055551, and HARICA confirmed the violation on 2026-07-20. HARICA said it briefly stopped issuance, restored the AIA OCSP URI to the affected TLS certificate profiles, and later updated CP/CPS version 4.14 to make the URI optional. HARICA stated that affected subscribers were notified, replacement certificates were issued where applicable, and revocation of the remaining affected certificates began on 2026-07-25 and was completed eight minutes later. HARICA also updated its change-management procedure so future certificate-profile changes require an explicit CP/CPS compatibility check and approval by both a Compliance Officer and a CA Engineer. The bug was later closed after HARICA posted a closure summary and CCADB issued a final call for comments.
- HARICA removed the AIA OCSP URI from its production TLS certificate profiles.
- Chrome Root Program raised a possible CP/CPS inconsistency about the AIA OCSP URI.
- HARICA confirmed the CP/CPS violation and restored the AIA OCSP URI to the affected TLS certificate profiles.
- HARICA completed revocation of the remaining affected certificates.
- HARICA completed the change-management action item for certificate profile changes.
- HARICA posted a closure summary and requested closure of the bug.
- The bug status was resolved with FIXED.
- HARICA — HARICA opened a preliminary incident report describing the CP/CPS mismatch, the affected certificate window, and planned replacement and revocation.
- HARICA — HARICA posted the full incident report, stating that all affected certificates had been revoked and that issuance had been briefly stopped.
- Community commenter — A commenter challenged the incident heuristic and said the report should be self-contained rather than referring to related incidents.
- HARICA — HARICA said the heuristic was an approximation, explained that some certificates were intentionally issued with OCSP URIs during pre-agreed windows, and said it was monitoring the bug for further questions or comments.
- HARICA — HARICA said the unique action item in this bug was completed on 2026-08-13 and proposed moving future updates to bug 2055551.
- HARICA — HARICA posted a closure summary stating that all action items were completed and requesting closure.
- CCADB representative — CCADB issued a final call for comments and said the bug would be closed on approximately 2026-08-31.
- The bug was marked RESOLVED with FIXED.