Open Bug 2061746 Opened 3 days ago Updated 21 hours ago

ACCV: Issuance of Server TLS Certificates with CP/CPS Discrepancies

Categories

(CA Program :: CA Certificate Compliance, task)

Tracking

(Not tracked)

ASSIGNED

People

(Reporter: jamador, Assigned: jamador)

Details

(Whiteboard: [ca-compliance] [__-misissuance])

Preliminary Incident Report


Summary

Incident description:

As a result of the ongoing process to include our new PKI hierarchy in Chrome’s Root Store, Chrome is conducting a detailed review of ACCV’s certification practices, policies, and publicly issued certificates, identifying potential discrepancies between ACCV’s published Certification Practices and Policies for Website Authentication Certificates and publicly trusted TLS certificates issued by ACCV. After some prior clarifications with the Chrome team, the potential discrepancies suggested by the Chrome team were as follows:

    • certificate serial numbers containing 20 octets, while the applicable CP/CPS describes serial numbers as 16-octet random values and, in the certificate profile tables, as containing fewer than 32 hexadecimal characters;
    • Subject Relative Distinguished Names whose relative ordering appears inconsistent with the ordering required by Sections 7.1.2 and 7.1.4.1 of the CP/CPS.

ACCV initiated an investigation immediately after receiving the answers. The initial phase of the investigation concluded 24 hours later (August 6, 2026), finding:

  • There are discrepancies.
  • All affected certificates were to be replaced and revoked within five days.

At the time of this preliminary report, the incident is considered CONTAINED.
As a precaution issuance using the potentially affected profiles was stopped on August 6, 2026.

Possible error is only in CP/CPS documents. CP/CPS documents are corrected on August 6, 2026, and issuance will be resume only after the corrected behavior had been verified.
 
Relevant policies:

Source of incident disclosure: ACCV as a result of the ongoing process to include our new PKI hierarchy in Chrome’s Root Store.

Assignee: nobody → jamador
Status: UNCONFIRMED → ASSIGNED
Ever confirmed: true
Whiteboard: [ca-compliance] [__-misissuance]
You need to log in before you can comment on or make changes to this bug.