CA/Incident Dashboard

From MozillaWiki
< CA
Jump to navigation Jump to search

Open CA Bugs in Bugzilla

There are three separate lists of open compliance bugs below:

  • Compliance bugs (not including audit delays or leaf revocation delays)
  • Audit Delays
  • Leaf Revocation Delays

Open CA Compliance Bugs

A CA compliance bug relates to a concern about a CA's certificates failing to comply with Mozilla's CA Certificate Policy and/or a CA/Browser Forum requirement, and is determined to not be an imminent security concern. A CA's response to a CA compliance bug includes providing an Incident Report in the bug.

Anyone may create a CA Compliance bug as follows:

View open CA compliance bugs in Bugzilla

Full Query
Summary ID Status Assigned to Whiteboard Last change time Creation time
ACCV: Issuance of Server TLS Certificates with CP/CPS Discrepancies 2061746 ASSIGNED jamador@accv.es [ca-compliance] [__-misissuance] 2026-08-19T14:01:16Z 2026-08-07T15:18:02Z
Actalis: failure to timely update CP/CPS for AgID SubCAs 2056934 ASSIGNED nicolo.papi@staff.aruba.it [ca-compliance] [policy-failure] 2026-08-19T16:18:53Z 2026-07-22T15:58:05Z
Actalis: Issuance of Server TLS Certificates with id-kp-clientAuth against CPS 2060581 ASSIGNED marco.menonna@staff.aruba.it [ca-compliance] [__-misissuance] 2026-08-14T16:05:46Z 2026-08-04T15:38:45Z
Actalis: Undisclosed Subordinate CA Certificate 2049960 ASSIGNED marco.menonna@staff.aruba.it [ca-compliance] [disclosure-failure] 2026-08-19T16:18:13Z 2026-06-24T07:17:21Z
Amazon Trust Services: CP/CPS missing explicit adherence to latest version of policies 2063908 ASSIGNED llopezam@amazon.de [ca-compliance] [policy-failure] 2026-08-17T17:12:05Z 2026-08-16T15:15:29Z
Asseco DS / Certum: Delayed publication of Full Incident Report for Bug 2055775 2059735 ASSIGNED kateryna.aleksieieva@assecods.pl [ca-compliance] [disclosure-failure] 2026-08-15T05:17:39Z 2026-07-31T12:57:43Z
Asseco DS / Certum: Incomplete CRL Disclosure in CCADB 2055775 ASSIGNED kateryna.aleksieieva@assecods.pl [ca-compliance] [disclosure-failure] Next update 2026-08-31 2026-08-13T15:13:38Z 2026-07-17T08:04:55Z
Asseco DS / Certum: Incorrect Country in certificate 2061178 ASSIGNED karolina.ruszczynska@assecods.pl [ca-compliance] [__-misissuance] 2026-08-19T18:43:03Z 2026-08-06T12:36:13Z
BEIJING CERTIFICATE AUTHORITY Co., Ltd.: Delayed publication of Full Incident Report for Bug 2056489 2060790 ASSIGNED zhangwenhua@bjca.org.cn [close on 2026-08-25] [ca-compliance] [policy-failure] [disclosure-failure] 2026-08-18T14:31:01Z 2026-08-05T09:09:07Z
BEIJING CERTIFICATE AUTHORITY Co., Ltd.: Failure to Respond to a Certificate Problem Report Within 24 Hours 2060785 ASSIGNED zhangwenhua@bjca.org.cn [close on 2026-08-25] [ca-compliance] [policy-failure] 2026-08-18T14:30:07Z 2026-08-05T09:03:10Z
BEIJING CERTIFICATE AUTHORITY Co., Ltd.: Incident Report - TLS Certificates Issued with RSA Public Exponent 3 2056489 ASSIGNED zhangwenhua@bjca.org.cn [close on 2026-08-21] [ca-compliance] [uncategorized] 2026-08-14T15:29:31Z 2026-07-21T08:38:23Z
Certainly: Missing audit log entries for certificates issued during capacity testing 2052085 ASSIGNED djeffery@fastly.com [ca-compliance] [uncategorized] 2026-08-14T22:33:57Z 2026-07-02T01:57:59Z
Certainly: Test Website Certificate Renewal Failure Following Production Deployment Drift 2061909 ASSIGNED djeffery@fastly.com [ca-compliance] [policy-failure] 2026-08-14T22:22:04Z 2026-08-08T01:06:48Z
CFCA: Delayed response to CPR related with bug 2058918 2058920 ASSIGNED songxinlei@cfca.com.cn [ca-compliance] [policy-failure] 2026-08-17T01:47:33Z 2026-07-29T13:53:34Z
CFCA: Incorrect countryName values in OV subscriber certificates 2058918 ASSIGNED songxinlei@cfca.com.cn [ca-compliance] [ov-misissuance] 2026-08-17T01:47:08Z 2026-07-29T13:44:15Z
Chunghwa Telecom: Incomplete disclosure of CRL URLs in CCADB 2055120 ASSIGNED tmkuo@cht.com.tw [close on 2026-08-21] [ca-compliance] [disclosure-failure] 2026-08-14T15:31:24Z 2026-07-15T03:50:50Z
D-Trust: CRL URL Disclosure 2007116 ASSIGNED ana-laura.martorano@d-trust.net [ca-compliance] [disclosure-failure] 2026-08-14T08:24:07Z 2025-12-19T14:22:17Z
D-TRUST: Incomplete Disclosure of CRL URLs 2055250 ASSIGNED Frank.Meissen@bdr.de [ca-compliance] [disclosure-failure] Next update 2026-10-01 2026-08-14T08:26:33Z 2026-07-15T15:23:31Z
D-Trust: Missing Pre-Sign Linting for S/MIME Issuing CAs 2037000 ASSIGNED ana-laura.martorano@d-trust.net [ca-compliance] [smime-misissuance] 2026-08-13T20:50:19Z 2026-05-05T07:56:12Z
D-Trust: Missing Pre-Signing Linting for TLS Issuance 2029013 ASSIGNED enrico.entschew@bdr.de [ca-compliance] [policy-failure] Next update 2026-08-29 2026-08-16T20:33:08Z 2026-04-02T20:50:08Z
DigiCert: Blank SubCA Owner field in CCADB for cross-certificate 2058363 ASSIGNED dcbugzillaresponse@digicert.com [ca-compliance] [disclosure-failure] 2026-08-14T16:05:49Z 2026-07-28T01:40:00Z
DigiCert: jurisdictionCountry in EV certificate 2062100 ASSIGNED dcbugzillaresponse@digicert.com [ca-compliance] [ev-misissuance] 2026-08-19T20:11:22Z 2026-08-10T00:13:15Z
Disig: CP/CPS misstatement regarding Key Usage criticality for TLS certificates 2056087 ASSIGNED peter.miskovic@disig.sk [ca-compliance] [policy-failure] 2026-08-14T14:08:59Z 2026-07-19T16:07:31Z
eMudhra emSign PKI Services: Invalid Subject Locality/State Values 2057520 ASSIGNED naveen.ml@emudhra.com [ca-compliance] [ov-misissuance] 2026-08-14T12:12:50Z 2026-07-24T13:51:03Z
eMudhra emSign PKI Services: www Subdomain Inclusion in Certificate SAN via ACME Issuance Workflow 2043837 ASSIGNED naveen.ml@emudhra.com [ca-compliance] [policy-failure] Next update 2026-08-31 2026-07-23T15:45:05Z 2026-05-30T15:22:39Z
Firmaprofesional: Chrome Root Progam Policy - Dedicated TLS hierarchy / EKU requirements 2054448 UNCONFIRMED nobody@mozilla.org Next update 2026-08-31 [ca-compliance] 2026-07-28T12:59:08Z 2026-07-13T11:10:25Z
Firmaprofesional: Chrome Root Program Policy - Incorrect CCADB hierarchy associations 2054450 ASSIGNED clopez@firmaprofesional.com [ca-compliance] [disclosure-failure] 2026-08-19T12:31:42Z 2026-07-13T11:16:39Z
Firmaprofesional: Delayed publication of 2026 Audit Attestation Letters 2055444 ASSIGNED clopez@firmaprofesional.com Next update 2026-08-21 [ca-compliance] [disclosure-failure] 2026-07-30T12:31:09Z 2026-07-16T11:05:52Z
FNMT: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy 2056989 ASSIGNED amaya.espinosa@fnmt.es [ca-compliance] [ca-misissuance] 2026-08-13T10:15:11Z 2026-07-22T18:42:25Z
GlobalSign: SubCA created with incorrect CPS Policy OID 2058503 ASSIGNED pki-notifications@globalsign.com Next update 2026-08-18 [ca-compliance] [ca-misissuance] 2026-08-18T18:53:03Z 2026-07-28T13:57:22Z
GlobalSign: Unicode replacement character issue in Subject 2057318 ASSIGNED pki-notifications@globalsign.com [ca-compliance] [__-misissuance] Next update 2026-08-27 2026-08-13T15:17:20Z 2026-07-23T19:08:14Z
GoDaddy: CRL Disclosure in CCADB Mismatch with Issued Certificates 2007216 ASSIGNED sdeitte@godaddy.com [ca-compliance] [disclosure failure] Next update 2026-09-15 2026-07-01T21:04:41Z 2025-12-20T00:13:07Z
Google Trust Services: CPS Missing root program attestation 2058261 ASSIGNED gts-external@google.com Next update 2026-08-30 [ca-compliance] [policy-failure] 2026-08-11T18:35:05Z 2026-07-27T18:55:10Z
HARICA: Issuance of Server TLS Certificates with id-kp-clientAuth KeyPurposeID against CP/CPS 2055551 ASSIGNED public-incident-reports@harica.gr [ca-compliance] [__-misissuance] Next update 2026-09-18 2026-08-14T23:47:56Z 2026-07-16T15:33:56Z
HARICA: Issuance of Server TLS Certificates without AIA OCSP URI against CP/CPS 2056668 ASSIGNED public-incident-reports@harica.gr [ca-compliance] [__-misissuance] 2026-08-14T15:54:31Z 2026-07-21T18:56:01Z
IdenTrust: Delayed disclosure of Intermediate CA in CCADB 2053948 ASSIGNED roots@identrust.com [ca-compliance] [disclosure-failure] Next update 2026-09-18 2026-07-29T16:38:11Z 2026-07-09T22:42:41Z
iTrusChina: Inconsistent EKUs in CP/CPS and Mis-issuance of TLS Certificates with clientAuth against CP/CPS 2060152 ASSIGNED vTrus_contact@itrus.cn [ca-compliance] [__-misissuance] 2026-08-17T00:55:42Z 2026-08-03T09:35:00Z
Let's Encrypt: CPS missing root program attestation 2062418 NEW aaron@letsencrypt.org Next update 2026-08-24 [ca-compliance] [policy-failure] 2026-08-16T12:30:56Z 2026-08-10T20:03:07Z
Let's Encrypt: CRLs Temporarily Missing Revoked Serials 2044788 ASSIGNED pporada@letsencrypt.org [ca-compliance] [crl-failure] Next update 2026-09-30 2026-07-24T20:56:18Z 2026-06-03T19:40:25Z
Let's Encrypt: Gen Y Cross-Certified Subordinate CAs missing serverAuth EKU 2038351 ASSIGNED pporada@letsencrypt.org [ca-compliance] [ca-misissuance] Next update 2026-08-21 2026-08-19T12:43:22Z 2026-05-08T21:28:16Z
Microsoft PKI Services: Third-Party Code Signing CPS missed annual update and four Issuing CAs 2059818 ASSIGNED qaalhajr@microsoft.com [ca-compliance] [policy-failure] 2026-08-14T16:27:04Z 2026-07-31T17:53:54Z
Netlock: CA in AIA in PEM format 2004699 ASSIGNED kaluha.roland@netlock.hu [ca-compliance] [policy-failure] 2026-08-10T22:50:23Z 2025-12-08T13:50:23Z
NETLOCK: Failure to file a preliminary incident report within 72 hours (OCSP responder incident, Bug 2051459) 2063842 ASSIGNED fruvald.levente@netlock.hu [ca-compliance] [policy-failure] 2026-08-17T17:15:41Z 2026-08-15T21:02:48Z
NETLOCK: Failure to Respond to a Certificate Problem Report Within 24 Hours 2052541 ASSIGNED kaluha.roland@netlock.hu [ca-compliance] [policy-failure] [external] 2026-08-05T22:51:54Z 2026-07-03T14:21:44Z
NETLOCK: OCSP Service Returning Error for Issued Certificate 2051459 ASSIGNED kaluha.roland@netlock.hu [ca-compliance] [ocsp-failure] [external] 2026-08-20T05:14:14Z 2026-06-30T00:29:01Z
SDAIA: Missing S/MIME WebTrust audit coverage 2056942 ASSIGNED Asofyani@sdaia.gov.sa [ca-compliance] [audit-failure] 2026-08-17T10:30:44Z 2026-07-22T16:17:03Z
Sectigo: Incorrect jurisdictionStateOrProvinceName attribute value in Code Signing certificate 2054098 ASSIGNED martijn.katerbarg@sectigo.com [ca-compliance] [cs-misissuance] Next update 2026-08-31 2026-08-18T16:03:50Z 2026-07-10T14:59:10Z
Sectigo: jurisdictionCountry versus organizationIdentifier mismatch in QWAC 2062202 ASSIGNED martijn.katerbarg@sectigo.com [ca-compliance] [ev-misissuance] 2026-08-10T13:47:33Z 2026-08-10T10:16:26Z
SHECA: Disclosure alerts indicating audit information missing for 2 Sub-CAs 2057433 ASSIGNED wangjiatai@sheca.com [ca-compliance] [disclosure-failure] Next update 2026-08-31 2026-08-11T18:34:31Z 2026-07-24T08:27:43Z
SHECA: Failed to provide a preliminary incident report within 72 hours 2057439 ASSIGNED wangjiatai@sheca.com [ca-compliance] [policy-failure] Next update 2026-08-31 2026-08-11T18:33:59Z 2026-07-24T08:50:59Z
SSL.com: Failure to respond to Certificate Problem Report within 24 hours 2057919 ASSIGNED secauditor@ssl.com [ca-compliance] [policy-failure] 2026-08-14T21:05:37Z 2026-07-26T21:49:02Z
SSL.com: Invalid Subject stateOrProvince Values 2057915 ASSIGNED secauditor@ssl.com [ca-compliance] [ov-misissuance] 2026-08-14T21:22:33Z 2026-07-26T21:29:51Z
SwissSign: Invalid Entry in State field 2057448 ASSIGNED sandy.balzer@swisssign.com [ca-compliance] [ov-misissuance] 2026-08-19T14:27:05Z 2026-07-24T09:13:21Z

53 Total; 53 Open (100%); 0 Resolved (0%); 0 Verified (0%);


Audit Delays

The compliance bug's whiteboard field is tagged with [audit-delay] whenever a CA is unable to deliver audit statements to Mozilla when they are due. Such bugs should be reported as CA compliance issues, with the following whiteboard tags as described here.

  • Whiteboard = [ca-compliance][audit-delay]
  • For audit delays due to mandated restrictions regarding COVID-19, use Whiteboard = [ca-compliance][audit-delay][covid-19]

View audit delay bugs in Bugzilla

Full Query
Summary ID Status Assigned to Whiteboard Last change time Creation time
D-Trust: Delayed publication of audit attestation letters in the CCADB 2011430 ASSIGNED ana-laura.martorano@d-trust.net [ca-compliance] [audit-delay] Next update 2026-10-02 2026-08-03T15:50:41Z 2026-01-20T14:51:29Z

1 Total; 1 Open (100%); 0 Resolved (0%); 0 Verified (0%);


Revocation Delays

The compliance bug's whiteboard field is tagged with [ca-revocation-delay] or [leaf-revocation-delay] whenever a CA fails to abide by Mozilla's requirement to revoke certificates in a timely fashion. As discussed in CA/Responding_To_An_Incident#Revocation, Mozilla recognizes that there may be *exceptional* situations that cause a CA to not abide by the Baseline Requirements, which should be accompanied by an Incident Report.

Such bugs should be reported as CA compliance issues, and will be categorized appropriately during triage.

View revocation delay bugs in Bugzilla

Full Query
Summary ID Status Assigned to Whiteboard Last change time Creation time
SDAIA: Delayed Revocation related to Bugzilla #2056942 2058294 ASSIGNED Asofyani@sdaia.gov.sa [ca-compliance] [leaf-revocation-delay] 2026-08-16T16:55:10Z 2026-07-27T21:00:04Z
SwissSign: Delayed revocation related to Bugzilla 2033000 2034359 ASSIGNED michael.guenther@swisssign.com [ca-compliance] [leaf-revocation-delay] Next update 2026-09-30 2026-08-17T10:38:49Z 2026-04-23T08:14:19Z

2 Total; 2 Open (100%); 0 Resolved (0%); 0 Verified (0%);


Closed CA Bugs

Closed CA Compliance Bugs

A historical view of past CA compliance bugs may be found here: