ACCV: Issuance of Server TLS Certificates with CP/CPS Discrepancies
Categories
(CA Program :: CA Certificate Compliance, task)
Tracking
(Not tracked)
People
(Reporter: jamador, Assigned: jamador)
Details
(Whiteboard: [ca-compliance] [__-misissuance])
Preliminary Incident Report
Summary
Incident description:
As a result of the ongoing process to include our new PKI hierarchy in Chrome’s Root Store, Chrome is conducting a detailed review of ACCV’s certification practices, policies, and publicly issued certificates, identifying potential discrepancies between ACCV’s published Certification Practices and Policies for Website Authentication Certificates and publicly trusted TLS certificates issued by ACCV. After some prior clarifications with the Chrome team, the potential discrepancies suggested by the Chrome team were as follows:
• certificate serial numbers containing 20 octets, while the applicable CP/CPS describes serial numbers as 16-octet random values and, in the certificate profile tables, as containing fewer than 32 hexadecimal characters;
• Subject Relative Distinguished Names whose relative ordering appears inconsistent with the ordering required by Sections 7.1.2 and 7.1.4.1 of the CP/CPS.
ACCV initiated an investigation immediately after receiving the answers. The initial phase of the investigation concluded 24 hours later (August 6, 2026), finding:
- There are discrepancies.
- All affected certificates were to be replaced and revoked within five days.
At the time of this preliminary report, the incident is considered CONTAINED.
As a precaution issuance using the potentially affected profiles was stopped on August 6, 2026.
Possible error is only in CP/CPS documents. CP/CPS documents are corrected on August 6, 2026, and issuance will be resume only after the corrected behavior had been verified.
Relevant policies:
- Affected policies CP/CPS 4.0.22 and earlier
https://www.accv.es/en/fileadmin/Archivos/Practicas_de_certificacion/ACCV-CPS-CP-V4.0.22-EN-2026.pdf - New policy
https://www.accv.es/en/fileadmin/Archivos/Practicas_de_certificacion/ACCV-CPS-CP-V4.0.23-EN-2026.pdf
Source of incident disclosure: ACCV as a result of the ongoing process to include our new PKI hierarchy in Chrome’s Root Store.
Updated•21 hours ago
|
Description
•