HARICA CPR handling: first response did not clearly convey triage findings
This case concerns HARICA’s handling of a Certificate Problem Report about alleged duplicate Distinguished Names in TLS server certificates. The reporter argued that HARICA’s CPS required unique DNs per issuing CA and that the affected certificates should be revoked. HARICA said it received the CPR on 2026-08-01, triaged it, sent a first response three hours and forty-three minutes later, and issued its final determination on 2026-08-04. HARICA and the reporter then focused on whether the first response satisfied BR section 4.9.5’s requirement to provide a preliminary report on findings within 24 hours. HARICA agreed that a preliminary report should convey findings and acknowledged that its first response did not clearly state the triage outcome, even though it said the triage had been performed. HARICA said it would revise its CPR first-response templates so the triage outcome is stated more clearly. Mozilla later suggested closing the bug as INVALID on or about 2026-08-28 unless further information or objections were raised, and the bug is now resolved INVALID.
- A Certificate Problem Report was sent to HARICA about duplicate Distinguished Names in subscriber certificates.
- HARICA received the CPR, triaged it, and sent a first response within 24 hours.
- HARICA sent its final determination after completing the investigation.
- Community commenter — The reporter said HARICA’s CPS requires unique Distinguished Names and claimed the CPR was not answered for almost three days.
- HARICA — HARICA said it received the CPR, responded within three hours and forty-three minutes, and saw no section 4.9.5 violation.
- Community commenter — The commenter argued that HARICA’s first response was only an acknowledgement and did not report findings as required by section 4.9.5.
- HARICA — HARICA agreed that a preliminary report should convey findings and said it would revise its first-response templates to state triage outcomes more clearly.
- Mozilla representative — Mozilla suggested closing the bug as INVALID on or about 2026-08-28 unless further information or objections were raised.