Open Bug 2069774 Opened 7 days ago Updated 16 hours ago

TWCA: CPR subject.countryName

Categories

(CA Program :: CA Certificate Compliance, task)

Tracking

(Not tracked)

ASSIGNED

People

(Reporter: CA, Assigned: CA)

Details

(Whiteboard: [ca-compliance])

Preliminary Incident Report

Summary

  • Incident description:

    • On 2026-09-05, an external reporter alleged that certificates with dependent territory codes (e.g., HK, MO, KY) constitute mis-issuance, arguing they lack United Nations (UN) member state status under the definition in BR Section 1.6.1.

    • TWCA determined these certificates strictly comply with BR Section 7.1.2.7, which normatively mandates ISO 3166-1 alpha-2 codes. Because the encoded codes are officially listed on the ISO Online Browsing Platform, which covers both sovereign states and dependent territories, TWCA does not consider these certificates mis-issued, and no revocation is planned. This report is filed for transparency following broader community inquiries.

  • Relevant policies:

    • TLS BR Section 1.6.1 (Definitions - Country)
    • TLS BR Section 7.1.2.7 (Subscriber Certificate Subject attributes)
    • ISO 3166-1 alpha-2 (Codes for the representation of names of countries and their subdivisions – Part 1: Country codes)
  • Source of incident disclosure:
    Third Party Reported

Timeline

All times below are in UTC+0:

  • 2026-09-05 07:00: Reporter emailed TWCA claiming territory codes violate BR 1.6.1, demanding certificate revocation and a Bugzilla incident.
  • 2026-09-05 09:26: TWCA emailed Reporter explaining that ISO 3166-1 alpha-2 codes under BR 7.1.2.7 cover territories, refuting mis-issuance.
  • 2026-09-05 14:03: Reporter emailed TWCA rejecting the response, demanding TWCA re-read the BR definition and open a Bugzilla ticket.
  • 2026-09-05 21:41: TWCA emailed Reporter clarifying Section 1.6.1 covers validation while 7.1.2.7 governs encoding, concluding the certificates are fully compliant and this is not an incident.
  • 2026-09-07 00:20: TWCA published the Preliminary Incident Report on Bugzilla for transparency.

TWCA aligns with the perspective detailed in Bug 2069766. We do not consider this a compliance incident, and if our position aligns with the community's understanding, we request that this bug be closed as INVALID.

Assignee: nobody → CA
Status: UNCONFIRMED → ASSIGNED
Type: defect → task
Ever confirmed: true
Whiteboard: [ca-compliance]
  • 2026-09-07 00:42: We informed the reporter that a Bugzilla ticket has been opened, but haven't received any response as of this update.

We're tracking this issue and two others with the same root cause (bug 2069766 and bug 2070071).

You need to log in before you can comment on or make changes to this bug.