Open
Bug 2056668
Opened 2 days ago
Updated 12 hours ago
HARICA: Issuance of Server TLS Certificates without AIA OCSP URI against CP/CPS
Categories
(CA Program :: CA Certificate Compliance, task)
CA Program
CA Certificate Compliance
Tracking
(Not tracked)
UNCONFIRMED
People
(Reporter: public-incident-reports, Unassigned)
Details
Preliminary Incident Report
Summary
- Incident description: On 2026-07-17, the Chrome Root Program team reported a possible inconsistency in the CP/CPS language regarding AIA OCSP URI. In alignment with industry best practices, HARICA removed the AIA OCSP URI from its TLS Certificate profiles. However, we failed to update Section 7.1.2.3 of the CP/CPS to reflect that this inclusion is now optional.
All TLS Certificates issued after 2026-03-27 09:31:01 (EST) -timestamp when AIA OCSP URI was removed from the profiles- and a notBefore of 2026-07-20 22:53 (EEST) -timestamp when AIA OCSP URI was added back to the profiles- are affected and will be replaced and revoked as required by the BRs.
A full incident report will be posted no later than 2026-07-31.
- Relevant policies: Section 7.1.2.3 of the HARICA CP/CPS (before version 4.14)
- Source of incident disclosure: Third-party reported, on an existing bug https://bugzilla.mozilla.org/show_bug.cgi?id=2055551
You need to log in
before you can comment on or make changes to this bug.
Description
•