← HARICA cases
Bugzilla #2056668 Policy Document Issue Incident Self Reported Incident Certificate Misissuance

HARICA preliminary incident report: CP/CPS mismatch for AIA OCSP URI in TLS certificate profiles

UNCONFIRMED HARICA
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

HARICA filed a preliminary incident report about a mismatch between its TLS certificate profiles and its CP/CPS language for the AIA OCSP URI. HARICA says the Chrome Root Program team reported a possible inconsistency on 2026-07-17, after HARICA had removed the AIA OCSP URI from its TLS Certificate profiles. HARICA states it failed to update Section 7.1.2.3 of the CP/CPS to reflect that the inclusion is now optional. HARICA says all TLS certificates issued after 2026-03-27 09:31:01 EST and before 2026-07-20 22:53 EEST are affected, and that those certificates will be replaced and revoked as required by the Baseline Requirements. HARICA also said a full incident report would be posted no later than 2026-07-31. The bug remains UNCONFIRMED.

Model: gpt-5.4-mini Generated: 2026-07-26 06:25 UTC Confidence: 0.93 1 comment
Chronology
  1. Chrome Root Program reported a possible CP/CPS inconsistency about AIA OCSP URI in HARICA TLS certificate profiles.
  2. HARICA removed the AIA OCSP URI from its TLS certificate profiles.
  3. HARICA added the AIA OCSP URI back to its TLS certificate profiles.
Thread Activity
  1. HARICA — HARICA opened a preliminary incident report describing the CP/CPS mismatch, identifying affected certificates, and saying they will be replaced and revoked.
Participants
HARICA
Related Bugzilla IDs Mentioned
Similar Local Cases
#2029643 RESOLVED Self Reported Incident Revocation Issue Certificate Misissuance Opened 2026-04-06 · Closed 2026-05-22 · 90% similar
HARICA: Incorrect Open MPIC Lambda implementation by EJBCA ACME Service
#2017845 RESOLVED Certificate Misissuance Self Reported Incident Problem Reporting Failure Opened 2026-02-19 · Closed 2026-06-29 · 89% similar
HARICA: Incorrect nCAId in PSD2 QCStatement for QWACs
#1699796 RESOLVED Self Reported Incident Certificate Misissuance Opened 2021-03-19 · Closed 2023-02-22 · 81% similar
HARICA: Certificates with invalid policy tree
#1580393 RESOLVED Incident Self Reported Incident Opened 2019-09-11 · Closed 2022-11-14 · 80% similar
HARICA: OCSP Responder Returned "Unauthorized" for Some Precertificates
#1535772 RESOLVED Incident Certificate Misissuance Revocation Issue Opened 2019-03-15 · Closed 2023-02-22 · 79% similar
HARICA: wrong characters in NC extension of Technically Constrained Intermediate CA Certificates
#1597135 RESOLVED Certificate Misissuance Revocation Issue Incident Opened 2019-11-17 · Closed 2023-02-22 · 79% similar
HARICA: 3 EV TLS Certificates without L or ST
#1535509 RESOLVED Incident Certificate Misissuance Revocation Issue Opened 2019-03-15 · Closed 2023-02-22 · 78% similar
HARICA: Insufficient serial number entropy
#1943604 RESOLVED Certificate Misissuance Opened 2025-01-24 · Closed 2025-05-25 · 76% similar
HARICA: TLS Server certificate issuance without proper validation

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action