← Government of Spain, Autoritat de Certificació de la Comunitat Valenciana (ACCV) cases
Bugzilla #2061746 Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Revocation Issue

ACCV preliminary incident report on TLS certificate CP/CPS discrepancies

ASSIGNED Government of Spain, Autoritat de Certificació de la Comunitat Valenciana (ACCV)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

ACCV opened this bug as a preliminary incident report after Chrome’s review of its publicly issued TLS certificates and published CP/CPS identified potential discrepancies. The issues described were certificate serial numbers appearing to use 20 octets instead of the CP/CPS-described 16-octet random values, and Subject Relative Distinguished Name ordering that may not match the CP/CPS requirements. ACCV said it began an investigation immediately after receiving Chrome’s questions and concluded the initial phase 24 hours later, finding that discrepancies did exist. The report states that all affected certificates were to be replaced and revoked within five days, issuance using the potentially affected profiles was stopped on 2026-08-06, and the CP/CPS documents were corrected on 2026-08-06. ACCV also said the incident was considered contained and that issuance would resume only after the corrected behavior had been verified.

Model: gpt-5.4-mini Generated: 2026-08-10 11:45 UTC Confidence: 0.97 1 comment
Chronology
  1. ACCV stopped issuance using the potentially affected profiles and corrected the CP/CPS documents.
  2. ACCV concluded its initial investigation and determined that discrepancies existed.
  3. ACCV filed a preliminary incident report in Mozilla Bugzilla.
Thread Activity
  1. Government of Spain, Autoritat de Certificació de la Comunitat Valenciana (ACCV) — ACCV reported Chrome-identified discrepancies between its published CP/CPS and publicly trusted TLS certificates, said it had investigated, and stated that affected certificates would be replaced and revoked within five days.
Participants
Government of Spain, Autoritat de Certificació de la Comunitat Valenciana (ACCV)
Similar Local Cases
#1884532 RESOLVED Certificate Misissuance Opened 2024-03-09 · Closed 2024-07-11 · 77% similar
ACCV: Certificates issued with cRLIssuer in CDP extension
#1536213 RESOLVED Certificate Misissuance Opened 2019-03-18 · Closed 2023-02-22 · 76% similar
ACCV: Insufficient serial number entropy
#1889567 RESOLVED Self Reported Incident Opened 2024-04-04 · Closed 2024-08-28 · 76% similar
ACCV: Certificates issued with Policy qualifiers other than id-qt-cps
#2058503 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-07-28 Still Open · 72% similar
GlobalSign: SubCA created with incorrect CPS Policy OID
#2056223 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-07-20 · Closed 2026-08-08 · 72% similar
D-Trust OCSP Responder Certificates Include CA/B Forum DV Policy OID
#2057318 ASSIGNED Ca Certificate Compliance Externally Reported Incident Certificate Misissuance Validation Issue Opened 2026-07-23 Still Open · 71% similar
GlobalSign: Unicode replacement character issue in Subject
#2057520 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-07-24 Still Open · 71% similar
eMudhra emSign PKI Services: Invalid Subject Locality/State Values
#1921573 RESOLVED Self Reported Incident Policy Document Issue Opened 2024-09-27 · Closed 2024-11-06 · 71% similar
Let's Encrypt: No Meaningful Subject Distinguished Name

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action