HARICA TLS server certificate issuance and CPR response dispute over duplicate DNs
This case concerns a complaint that HARICA issued TLS server certificates with duplicate Distinguished Names that the reporter says violate HARICA’s CPS. The reporter said they raised the issue to HARICA’s Certificate Problem Report address on 2026-08-01 and initially believed HARICA did not reply for almost three days. HARICA responded that it received the CPR on 2026-08-01, sent a response three hours and forty-three minutes later, and issued its final determination on 2026-08-04 after investigation. HARICA stated that the CPR involved certificates across 13 issuing CAs and that it saw no violation of section 4.9.5 in its handling of the report. The thread does not show a resolution of the underlying duplicate-DN allegation in this bug; it focuses on whether HARICA met the CPR response and investigation requirements. The bug remains assigned to HARICA.
- A CPR was sent to HARICA about duplicate Distinguished Names in subscriber certificates across multiple issuing CAs.
- HARICA received the CPR and sent an initial response the same day.
- HARICA issued its final determination after completing its investigation.
- Community commenter — The reporter alleged that HARICA’s CPS requires unique Distinguished Names and said the CPR was not answered for almost three days.
- HARICA — HARICA said it received the CPR, responded within three hours and forty-three minutes, completed its investigation, and saw no section 4.9.5 violation.