← Government of Spain, Autoritat de Certificació de la Comunitat Valenciana (ACCV) cases
Bugzilla #2061746 Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Delayed Revocation

ACCV self-reported TLS CP/CPS non-compliance; remediation continues

ASSIGNED Government of Spain, Autoritat de Certificació de la Comunitat Valenciana (ACCV)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

ACCV reported a TLS certificate compliance incident after Chrome Root Program review identified discrepancies between ACCV’s binding CP/CPS and publicly trusted server TLS certificates it had issued. ACCV confirmed two discrepancies: 20-octet serial numbers where its CP/CPS described 16-octet random serials, and a Subject RDN ordering difference from the order made normative in the CP/CPS. ACCV said the affected certificates were not issued in accordance with its own CP/CPS, corrected the CP/CPS on 2026-08-06, and stopped issuance using the affected profiles while it investigated. ACCV later revised its full incident report to say the originally disclosed affected population was incomplete because it had not been fully reconciled against CT-only precertificates; it identified 137 additional CT-only precertificates and said every corresponding issuer-and-serial-number combination has been revoked. The thread also records that the delayed-revocation issue is tracked separately in Bugzilla #2064673. ACCV’s latest updates say remediation work is still ongoing, including revising the TLS CP/CPS, updating application logic, and improving the mass-revocation process.

Model: gpt-5.4-mini Generated: 2026-08-10 11:45 UTC Revised: 2026-09-20 07:00 UTC Confidence: 0.98 15 comments
Chronology
  1. ACCV began issuing certificates under the affected policy language with the serial-number discrepancy.
  2. Chrome Root Program notified ACCV of potential discrepancies between issued certificates and ACCV’s CP/CPS.
  3. ACCV confirmed the non-compliance and published corrected CP/CPS version 4.0.23.
  4. ACCV completed revocation of the original population of affected final certificates.
  5. ACCV revoked additional affected precertificates identified after expanding the investigation.
Thread Activity
  1. Government of Spain, Autoritat de Certificació de la Comunitat Valenciana (ACCV) — ACCV opened a preliminary incident report describing Chrome-identified CP/CPS discrepancies and said affected certificates would be replaced and revoked within five days.
  2. Government of Spain, Autoritat de Certificació de la Comunitat Valenciana (ACCV) — ACCV filed a full incident report stating the certificates were not issued in accordance with its CP/CPS and that the issue was third-party reported during Chrome Root Program review.
  3. Community commenter — A commenter said the revocation timeline appeared to miss the five-day deadline and asked why some affected precertificates were not on the revocation lists.
  4. Government of Spain, Autoritat de Certificació de la Comunitat Valenciana (ACCV) — ACCV accepted the 2026-08-04 15:07 CEST notice as the revocation start date, acknowledged delayed revocation, and said the original affected population was incomplete.
  5. Google representative — Chrome Root Program asked about several revocations that appeared to lack a reasonCode and expected CRLReason superseded.
  6. Government of Spain, Autoritat de Certificació de la Comunitat Valenciana (ACCV) — ACCV said the questioned certificates had already been revoked by subscribers before the mass revocation batch and explained the reasonCode differences.
  7. Government of Spain, Autoritat de Certificació de la Comunitat Valenciana (ACCV) — ACCV posted a revised full incident report that superseded the prior report, corrected the revocation timeline and affected population, and said the delayed-revocation incident is tracked separately in Bugzilla #2064673.
  8. Government of Spain, Autoritat de Certificació de la Comunitat Valenciana (ACCV) — ACCV said it is still working on corrective actions, including revising its TLS CP/CPS, application logic, and mass-revocation process.
  9. Government of Spain, Autoritat de Certificació de la Comunitat Valenciana (ACCV) — ACCV said work on the planned remediation actions is continuing, including drafting the updated policy, preparing Git deployment, and coordinating application changes.
  10. Government of Spain, Autoritat de Certificació de la Comunitat Valenciana (ACCV) — ACCV said it continued work on CP/CPS-to-production reconciliation and noted a new cross-certificate for the 2024 TLS hierarchy as part of the transition work.
Participants
Government of Spain, Autoritat de Certificació de la Comunitat Valenciana (ACCV) Google representative Community commenter
Related Bugzilla IDs Mentioned
Similar Local Cases
#2057448 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-07-24 Still Open · 81% similar
SwissSign: Invalid Entry in State field
#2055551 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-07-16 Still Open · 80% similar
HARICA: Issuance of Server TLS Certificates with id-kp-clientAuth KeyPurposeID against CP/CPS
#2007116 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Ccadb Disclosure Issue Opened 2025-12-19 · Closed 2026-09-03 · 79% similar
D-Trust: CRL URL Disclosure
#1951415 RESOLVED Certificate Misissuance Delayed Revocation Opened 2025-03-03 · Closed 2025-05-08 · 79% similar
Chunghwa Telecom: Failure to check restrictive CAA record during Migration
#2051459 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Security Incident Opened 2026-06-30 Still Open · 78% similar
NETLOCK: OCSP Service Returning Error for Issued Certificate
#1962829 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Policy Document Issue Opened 2025-04-26 · Closed 2026-04-26 · 78% similar
Microsoft PKI Services: Policy document bug
#2009941 RESOLVED Certificate Misissuance Self Reported Incident Opened 2026-01-13 · Closed 2026-04-06 · 78% similar
Firmaprofesional: Misissuance of TLS Subordinate CA "AC Firmaprofesional - Secure Web 2024"
#1981680 RESOLVED Ca Certificate Compliance Self Reported Incident Certificate Misissuance Linting Quality Issue Opened 2025-08-07 · Closed 2025-09-26 · 78% similar
TunTrust: SSL OV mis-issuance against CP/CPS (Email attribute)

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

⚠

Confirm action