← HARICA cases
Bugzilla #2062162 Problem Reporting Failure Incident Externally Reported Incident Opened By Subscriber Or Relying Party Single Ca Owner

HARICA CPR handling: first response did not clearly convey triage findings

RESOLVED INVALID HARICA
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns HARICA’s handling of a Certificate Problem Report about alleged duplicate Distinguished Names in TLS server certificates. The reporter argued that HARICA’s CPS required unique DNs per issuing CA and that the affected certificates should be revoked. HARICA said it received the CPR on 2026-08-01, triaged it, sent a first response three hours and forty-three minutes later, and issued its final determination on 2026-08-04. HARICA and the reporter then focused on whether the first response satisfied BR section 4.9.5’s requirement to provide a preliminary report on findings within 24 hours. HARICA agreed that a preliminary report should convey findings and acknowledged that its first response did not clearly state the triage outcome, even though it said the triage had been performed. HARICA said it would revise its CPR first-response templates so the triage outcome is stated more clearly. Mozilla later suggested closing the bug as INVALID on or about 2026-08-28 unless further information or objections were raised, and the bug is now resolved INVALID.

Model: gpt-5.4-mini Generated: 2026-08-16 08:19 UTC Revised: 2026-09-06 07:01 UTC Confidence: 0.96 5 comments
Chronology
  1. A Certificate Problem Report was sent to HARICA about duplicate Distinguished Names in subscriber certificates.
  2. HARICA received the CPR, triaged it, and sent a first response within 24 hours.
  3. HARICA sent its final determination after completing the investigation.
Thread Activity
  1. Community commenter — The reporter said HARICA’s CPS requires unique Distinguished Names and claimed the CPR was not answered for almost three days.
  2. HARICA — HARICA said it received the CPR, responded within three hours and forty-three minutes, and saw no section 4.9.5 violation.
  3. Community commenter — The commenter argued that HARICA’s first response was only an acknowledgement and did not report findings as required by section 4.9.5.
  4. HARICA — HARICA agreed that a preliminary report should convey findings and said it would revise its first-response templates to state triage outcomes more clearly.
  5. Mozilla representative — Mozilla suggested closing the bug as INVALID on or about 2026-08-28 unless further information or objections were raised.
Participants
Community commenter HARICA Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#2052541 ASSIGNED Problem Reporting Failure Incident Self Reported Incident Remediation Tracking Opened 2026-07-03 Still Open · 79% similar
NETLOCK: Failure to Respond to a Certificate Problem Report Within 24 Hours
#2048995 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Problem Reporting Failure Opened 2026-06-19 · Closed 2026-07-30 · 79% similar
eMudhra emSign PKI Services: OCSP Responder Returned "Unauthorized" for Some Pecertificates
#2061907 RESOLVED Ca Certificate Compliance Incident Problem Reporting Failure Information Request Opened 2026-08-08 · Closed 2026-08-26 · 78% similar
Sectigo: Refusal to produce validation evidence for DV certificate issued via cPanel/WebPros subordinate CA (www.TradingExpertView.com, 2024-03-07)
#2049237 RESOLVED Ca Certificate Compliance Incident Externally Reported Incident Revocation Issue Opened 2026-06-22 · Closed 2026-07-29 · 76% similar
HARICA: Continued issuance and refusal to revoke TLS certificates for EU-sanctioned blocked entities (Sberbank, VTB, KAMAZ, ANO Dialog)
#2049179 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Problem Reporting Failure Opened 2026-06-21 · Closed 2026-08-04 · 76% similar
CFCA: OCSP Service return unauthorized responses
#2058920 RESOLVED Ca Certificate Compliance Incident Externally Reported Incident Problem Reporting Failure Opened 2026-07-29 · Closed 2026-09-24 · 72% similar
CFCA: Delayed response to CPR related with bug 2058918
#2055539 RESOLVED Problem Reporting Failure Incident Externally Reported Incident Revocation Issue Opened 2026-07-16 · Closed 2026-08-11 · 71% similar
DigiCert: Delayed availability of OCSP responses
#2065157 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Delayed Revocation Opened 2026-08-20 Still Open · 70% similar
SwissSign: Delayed revocation in Bug 2057448

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

⚠

Confirm action