Open Bug 2056668 Opened 2 days ago Updated 12 hours ago

HARICA: Issuance of Server TLS Certificates without AIA OCSP URI against CP/CPS

Categories

(CA Program :: CA Certificate Compliance, task)

Tracking

(Not tracked)

UNCONFIRMED

People

(Reporter: public-incident-reports, Unassigned)

Details

Preliminary Incident Report

Summary

  • Incident description: On 2026-07-17, the Chrome Root Program team reported a possible inconsistency in the CP/CPS language regarding AIA OCSP URI. In alignment with industry best practices, HARICA removed the AIA OCSP URI from its TLS Certificate profiles. However, we failed to update Section 7.1.2.3 of the CP/CPS to reflect that this inclusion is now optional.

All TLS Certificates issued after 2026-03-27 09:31:01 (EST) -timestamp when AIA OCSP URI was removed from the profiles- and a notBefore of 2026-07-20 22:53 (EEST) -timestamp when AIA OCSP URI was added back to the profiles- are affected and will be replaced and revoked as required by the BRs.

A full incident report will be posted no later than 2026-07-31.

You need to log in before you can comment on or make changes to this bug.