CA/Incident Dashboard
Open CA Bugs in Bugzilla
There are three separate lists of open compliance bugs below:
- Compliance bugs (not including audit delays or leaf revocation delays)
- Audit Delays
- Leaf Revocation Delays
Open CA Compliance Bugs
A CA compliance bug relates to a concern about a CA's certificates failing to comply with Mozilla's CA Certificate Policy and/or a CA/Browser Forum requirement, and is determined to not be an imminent security concern. A CA's response to a CA compliance bug includes providing an Incident Report in the bug.
Anyone may create a CA Compliance bug as follows:
- https://bugzilla.mozilla.org/enter_bug.cgi?product=CA+Program&component=CA+Certificate+Compliance&version=other
- Whiteboard = [ca-compliance]
- If the issue is due to mandated restrictions regarding COVID-19, use Whiteboard = [ca-compliance][covid-19]
| Summary | ID | Status | Assigned to | Whiteboard | Last change time | Creation time |
|---|---|---|---|---|---|---|
| Certigna: AIA CA issuer field pointing to PEM encoded cert | 2004732 | ASSIGNED | Josselin Allemandou | [ca-compliance] [policy-failure] | 2025-12-08T16:07:35Z | 2025-12-08T15:59:46Z |
| Certigna: Failure to respond to CPR within 24 hours | 2004704 | ASSIGNED | Josselin Allemandou | [ca-compliance] [policy-failure] [external] | 2025-12-08T19:26:30Z | 2025-12-08T14:16:42Z |
| eMudhra emSign PKI Services : Delayed Publication of Issuing CA Certificates in CCADB | 1999241 | ASSIGNED | Naveen Kumar ML | [ca-compliance] [disclosure-failure] | 2025-12-08T05:37:18Z | 2025-11-10T12:27:27Z |
| Financijska agencija (Fina): Mis-issued certificates | 1986968 | ASSIGNED | miroslav.perincic | [ca-compliance] [dv-misissuance] | 2025-12-07T12:02:12Z | 2025-09-04T16:47:06Z |
| GoDaddy: CA Certificates Published in PEM format | 2004845 | ASSIGNED | Steven Deitte | [ca-compliance] [policy-failure] | 2025-12-09T03:50:37Z | 2025-12-09T01:00:32Z |
| GoDaddy: Missing R1 Intermediate Full CRL URLs in CCADB | 2002402 | ASSIGNED | Steven Deitte | [ca-compliance] [disclosure-failure] | 2025-12-01T17:54:26Z | 2025-11-25T21:22:15Z |
| IdenTrust: CA Certificate not published in DER Encoded Format | 2004492 | ASSIGNED | IdenTrust | [ca-compliance] [policy-failure] | 2025-12-06T01:05:02Z | 2025-12-05T23:02:09Z |
| IdenTrust: TLS self audit testing below 3% | 1991558 | ASSIGNED | IdenTrust | [ca-compliance] [policy-failure] | 2025-11-26T14:37:12Z | 2025-09-29T23:04:25Z |
| IZENPE: not allowed Key Usage in ocsp responder certificate | 1996857 | ASSIGNED | David | [close on 2025-12-08] [ca-compliance] [ocsp-failure] | 2025-12-01T17:51:52Z | 2025-10-28T16:09:31Z |
| Microsoft PKI Services: End Entity Certificate Mis-issuance against CPS (BasicConstraints) | 1979475 | ASSIGNED | Microsoft PKI Services | [ca-compliance] [policy-failure] [ov-misissuance] | 2025-12-05T17:57:28Z | 2025-07-26T00:21:43Z |
| Microsoft PKI Services: Policy document bug | 1962829 | ASSIGNED | Microsoft PKI Services | [ca-compliance] [policy-failure] | 2025-12-05T19:31:38Z | 2025-04-26T02:10:29Z |
| Microsoft PKI Services: OCSP Non-Compliance | 1999850 | ASSIGNED | Microsoft PKI Services | [ca-compliance] [ocsp-failure] | 2025-12-05T17:58:14Z | 2025-11-13T01:29:14Z |
| NAVER Cloud Trust Services: CA Certificate not published in DER Encoded Format | 2004733 | ASSIGNED | Hogeun Yoo | [ca-compliance] [policy-failure] | 2025-12-08T16:06:12Z | 2025-12-08T16:04:05Z |
| NAVER Cloud Trust Services: Failure to respond to CPR within 24 hours | 2004698 | ASSIGNED | Hogeun Yoo | [ca-compliance] [policy-failure] [external] | 2025-12-08T15:37:28Z | 2025-12-08T13:49:22Z |
| Netlock: CA in AIA in PEM format | 2004699 | ASSIGNED | Roland | [ca-compliance] [policy-failure] | 2025-12-08T15:50:05Z | 2025-12-08T13:50:23Z |
| NETLOCK: Missing CDP Disclosure in CCADB | 2001327 | ASSIGNED | Roland | [ca-compliance] [disclosure-failure] | 2025-12-04T21:38:38Z | 2025-11-20T13:48:14Z |
| PKIoverheid: TSP Cleverbase Findings in 2025 ETSI Audit - Incident Report #1 – Incorrect issuer CA listed in CPS | 1985816 | ASSIGNED | Policy Authority PKIoverheid | [ca-compliance] [audit-finding] | 2025-11-11T15:27:18Z | 2025-08-28T15:39:28Z |
| PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #10 – Firewall Rules and Review | 1983270 | ASSIGNED | Policy Authority PKIoverheid | [ca-compliance] [audit-finding] | 2025-12-01T14:45:34Z | 2025-08-15T14:12:58Z |
| PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #11 – Anti-Malware Software | 1983271 | ASSIGNED | Policy Authority PKIoverheid | [ca-compliance] [audit-finding] | 2025-10-28T15:24:58Z | 2025-08-15T14:14:13Z |
| PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #15 – Outdated Software | 1983275 | ASSIGNED | Policy Authority PKIoverheid | [ca-compliance] [audit-finding] | 2025-12-01T14:44:46Z | 2025-08-15T14:18:19Z |
| PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #3 – Internal Audit | 1983263 | ASSIGNED | Policy Authority PKIoverheid | [ca-compliance] [audit-finding] | 2025-10-28T15:10:22Z | 2025-08-15T14:05:23Z |
| PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #7 – Change Management | 1983267 | ASSIGNED | Policy Authority PKIoverheid | [ca-compliance] [audit-finding] | 2025-12-02T00:22:10Z | 2025-08-15T14:09:40Z |
| PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #9 – Lifecycle Management | 1983269 | ASSIGNED | Policy Authority PKIoverheid | [ca-compliance] [audit-finding] | 2025-12-01T14:45:56Z | 2025-08-15T14:11:31Z |
| SECOM: Invalid stateOrProvinceName | 2004654 | ASSIGNED | SECOM Trust Systems - ONO Fumiaki | [ca-compliance] [ov-misissuance] | 2025-12-09T02:14:15Z | 2025-12-08T10:09:35Z |
| Sectigo: Certificate issuance by non-compliant Extant S/MIME CA | 2000277 | ASSIGNED | Martijn Katerbarg | [ca-compliance] [smime-misissuance] | 2025-12-04T11:51:49Z | 2025-11-14T18:04:01Z |
| Sectigo: Failure to reply to Certificate Problem Reports within 24 hours | 1994454 | ASSIGNED | Martijn Katerbarg | [close on 2025-12-10] [ca-compliance] [policy-failure] | 2025-12-03T18:15:43Z | 2025-10-15T15:41:07Z |
| SHECA: TLS certificate key generation online | 1993357 | ASSIGNED | SHECA | [ca-compliance] [dv-misissuance] [ov-misissuance] | 2025-12-08T12:13:11Z | 2025-10-08T19:46:26Z |
| SwissSign: Attribute Change process did not revoke single-domain certificates | 1995252 | ASSIGNED | Sandy Balzer | [close on 2025-12-11] [ca-compliance] | 2025-12-04T20:18:48Z | 2025-10-20T09:41:46Z |
| SwissSign: recommendation on backup testing | 1990272 | ASSIGNED | Sandy Balzer | [ca-compliance] [audit-finding] Next update 2026-04-30 | 2025-10-28T12:52:09Z | 2025-09-23T17:06:29Z |
| SwissSign: recommendation on BIA/BCP review | 1990263 | ASSIGNED | Sandy Balzer | [ca-compliance] [audit-finding] Next update 2026-04-30 | 2025-10-28T12:51:27Z | 2025-09-23T16:53:15Z |
| SwissSign: recommendation on BIA/BCP test coverage | 1990266 | ASSIGNED | Sandy Balzer | [ca-compliance] [audit-finding] Next update 2026-04-30 | 2025-10-28T12:51:38Z | 2025-09-23T16:55:40Z |
| SwissSign: recommendation on CA-specific risk assessment | 1990277 | ASSIGNED | Sandy Balzer | [ca-compliance] [audit-finding] Next update 2026-04-30 | 2025-10-28T12:52:51Z | 2025-09-23T17:08:41Z |
| SwissSign: recommendation on document release dual control | 1990269 | ASSIGNED | Sandy Balzer | [ca-compliance] [audit-finding] Next update 2026-04-30 | 2025-10-28T12:51:48Z | 2025-09-23T17:03:05Z |
| SwissSign: recommendation on evaluation of cloud service providers | 1990276 | ASSIGNED | Sandy Balzer | [ca-compliance] [audit-finding] Next update 2026-04-30 | 2025-10-28T12:52:39Z | 2025-09-23T17:08:11Z |
| SwissSign: recommendation on firewall review | 1990271 | ASSIGNED | Sandy Balzer | [ca-compliance] [audit-finding] Next update 2026-04-30 | 2025-10-28T12:51:54Z | 2025-09-23T17:05:31Z |
| SwissSign: recommendation on linting software updates | 1990282 | ASSIGNED | Sandy Balzer | [ca-compliance] [audit-finding] Next update 2026-04-30 | 2025-11-03T08:50:16Z | 2025-09-23T17:12:55Z |
| SwissSign: recommendation on log review process | 1990285 | ASSIGNED | Sandy Balzer | [ca-compliance] [audit-finding] Next update 2026-04-30 | 2025-10-28T12:54:20Z | 2025-09-23T17:14:00Z |
| SwissSign: recommendation on publication process for CA related data | 1990275 | ASSIGNED | Sandy Balzer | [ca-compliance] [audit-finding] Next update 2026-04-30 | 2025-10-28T12:52:27Z | 2025-09-23T17:07:40Z |
| SwissSign: recommendation on review of key pair generation implementation | 1990284 | ASSIGNED | Sandy Balzer | [ca-compliance] [audit-finding] Next update 2026-04-30 | 2025-10-28T12:53:56Z | 2025-09-23T17:13:29Z |
| SwissSign: recommendation on risk assessment | 1990254 | ASSIGNED | Sandy Balzer | [ca-compliance] [audit-finding] Next update 2026-04-30 | 2025-10-28T12:50:25Z | 2025-09-23T16:08:48Z |
| SwissSign: recommendation on self-assessment tool | 1990281 | ASSIGNED | Sandy Balzer | [ca-compliance] [audit-finding] Next update 2026-04-30 | 2025-10-28T12:53:00Z | 2025-09-23T17:12:19Z |
| SwissSign: recommendation on synchronization of staging and production environments | 1990274 | ASSIGNED | Sandy Balzer | [ca-compliance] [audit-finding] Next update 2026-04-30 | 2025-10-28T12:52:18Z | 2025-09-23T17:07:10Z |
| Telekom Security: Root-CA certificates published in PEM encoded format | 2004668 | ASSIGNED | Stefan Kirch | [ca-compliance] [policy-failure] | 2025-12-08T15:47:16Z | 2025-12-08T10:56:05Z |
| Telia: Delayed submission of preliminary audit incident report | 2004300 | ASSIGNED | Antti Backman | [ca-compliance] [policy-failure] | 2025-12-10T06:13:13Z | 2025-12-05T08:33:03Z |
| Telia: Findings in 2025 ETSI Audit - Incident Report #1 – Vulnerability management | 1999296 | ASSIGNED | Antti Backman | [ca-compliance] [audit-finding] Next update 2025-12-19 | 2025-12-05T21:30:24Z | 2025-11-10T15:09:58Z |
| TWCA: CA Certificate not published in DER Encoded Format | 2004521 | ASSIGNED | chtsai | [ca-compliance] [policy-failure] | 2025-12-08T15:51:48Z | 2025-12-06T06:30:14Z |
46 Total; 46 Open (100%); 0 Resolved (0%); 0 Verified (0%);
Audit Delays
The compliance bug's whiteboard field is tagged with [audit-delay] whenever a CA is unable to deliver audit statements to Mozilla when they are due. Such bugs should be reported as CA compliance issues, with the following whiteboard tags as described here.
- Whiteboard = [ca-compliance][audit-delay]
- For audit delays due to mandated restrictions regarding COVID-19, use Whiteboard = [ca-compliance][audit-delay][covid-19]
No results.
0 Total; 0 Open (0%); 0 Resolved (0%); 0 Verified (0%);
Revocation Delays
The compliance bug's whiteboard field is tagged with [ca-revocation-delay] or [leaf-revocation-delay] whenever a CA fails to abide by Mozilla's requirement to revoke certificates in a timely fashion. As discussed in CA/Responding_To_An_Incident#Revocation, Mozilla recognizes that there may be *exceptional* situations that cause a CA to not abide by the Baseline Requirements, which should be accompanied by an Incident Report.
Such bugs should be reported as CA compliance issues, and will be categorized appropriately during triage.
| Summary | ID | Status | Assigned to | Whiteboard | Last change time | Creation time |
|---|---|---|---|---|---|---|
| [meta] Delayed Revocation | 1911183 | ASSIGNED | Ben Wilson | [ca-compliance] [meta] [leaf-revocation-delay] | 2025-06-10T20:05:50Z | 2024-08-01T20:05:04Z |
| Microsoft PKI Services: Failure to Revoke in 5 Days for 1962829 | 1965612 | ASSIGNED | Microsoft PKI Services | [ca-compliance] [leaf-revocation-delay] | 2025-12-05T19:31:43Z | 2025-05-10T01:34:01Z |
| SHECA: Delayed revocation of TLS certificates affected by bug #1993357 | 1994051 | ASSIGNED | SHECA | [ca-compliance] [leaf-revocation-delay] | 2025-12-10T09:33:38Z | 2025-10-13T18:23:58Z |
| VikingCloud: Delayed revocation of TLS certificates in connection to bug #1883779 | 1885568 | ASSIGNED | VikingCloud CA | [ca-compliance] [ov-misissuance] [leaf-revocation-delay] | 2025-12-01T21:41:14Z | 2024-03-15T16:20:17Z |
4 Total; 4 Open (100%); 0 Resolved (0%); 0 Verified (0%);
Closed CA Bugs
Closed CA Compliance Bugs
A historical view of past CA compliance bugs may be found here: