ACCV preliminary incident report on TLS certificate CP/CPS discrepancies
ACCV opened this bug as a preliminary incident report after Chrome’s review of its publicly issued TLS certificates and published CP/CPS identified potential discrepancies. The issues described were certificate serial numbers appearing to use 20 octets instead of the CP/CPS-described 16-octet random values, and Subject Relative Distinguished Name ordering that may not match the CP/CPS requirements. ACCV said it began an investigation immediately after receiving Chrome’s questions and concluded the initial phase 24 hours later, finding that discrepancies did exist. The report states that all affected certificates were to be replaced and revoked within five days, issuance using the potentially affected profiles was stopped on 2026-08-06, and the CP/CPS documents were corrected on 2026-08-06. ACCV also said the incident was considered contained and that issuance would resume only after the corrected behavior had been verified.
- ACCV stopped issuance using the potentially affected profiles and corrected the CP/CPS documents.
- ACCV concluded its initial investigation and determined that discrepancies existed.
- ACCV filed a preliminary incident report in Mozilla Bugzilla.
- Government of Spain, Autoritat de Certificació de la Comunitat Valenciana (ACCV) — ACCV reported Chrome-identified discrepancies between its published CP/CPS and publicly trusted TLS certificates, said it had investigated, and stated that affected certificates would be replaced and revoked within five days.