CA/Incident Dashboard

From MozillaWiki
< CA
Jump to navigation Jump to search

Open CA Bugs in Bugzilla

There are three separate lists of open compliance bugs below:

  • Compliance bugs (not including audit delays or leaf revocation delays)
  • Audit Delays
  • Leaf Revocation Delays

Open CA Compliance Bugs

A CA compliance bug relates to a concern about a CA's certificates failing to comply with Mozilla's CA Certificate Policy and/or a CA/Browser Forum requirement, and is determined to not be an imminent security concern. A CA's response to a CA compliance bug includes providing an Incident Report in the bug.

Anyone may create a CA Compliance bug as follows:

Full Query
Summary ID Status Assigned to Whiteboard Last change time Creation time
Asseco DS / Certum: CRL URLs disclosed in CCADB do not exactly match the CRL URLs in certificates 2007105 ASSIGNED Kateryna Aleksieieva [ca-compliance] [disclosure-failure] 2025-12-19T15:08:34Z 2025-12-19T13:32:26Z
Buypass: Findings in 2025 ETSI Audit - Audit Incident Report #1 - Compliance auditing on support processes 2005194 ASSIGNED Mads Henriksveen [ca-compliance] [audit-finding] 2025-12-23T09:06:22Z 2025-12-10T13:20:20Z
Buypass: Findings in 2025 ETSI Audit - Audit Incident Report #2 - Supply chain policy 2005196 ASSIGNED Mads Henriksveen [ca-compliance] [audit-finding] 2025-12-23T09:06:32Z 2025-12-10T13:22:48Z
Certigna: AIA CA issuer field pointing to PEM encoded cert 2004732 ASSIGNED Josselin Allemandou [close on 2025-12-29] [ca-compliance] [policy-failure] 2025-12-22T21:09:56Z 2025-12-08T15:59:46Z
Certigna: CRL URL Disclosure 2007238 ASSIGNED Josselin Allemandou [ca-compliance] [disclosure failure] 2025-12-22T18:04:09Z 2025-12-20T11:13:03Z
Certigna: Failure to respond to CPR within 24 hours 2004704 ASSIGNED Josselin Allemandou [ca-compliance] [policy-failure] [external] 2025-12-20T11:47:59Z 2025-12-08T14:16:42Z
CFCA: DV OCA caIssuers Returns PEM Encoded Certificate (RFC 5280 Section 4.2.2.1 Violation) 2005399 ASSIGNED Michael [ca-compliance] [policy-failure] 2025-12-25T13:07:22Z 2025-12-11T02:49:24Z
CFCA: EV Certificates misissued with incorrect businessCategory 2006333 ASSIGNED Michael [ca-compliance] [ev-misissuance] 2025-12-22T08:48:12Z 2025-12-16T12:59:00Z
Chunghwa Telecom: CA Certificates Published in PEM format 2005567 ASSIGNED Tsung-Min Kuo [ca-compliance] [policy-failure] 2025-12-26T06:04:19Z 2025-12-11T17:01:10Z
Chunghwa Telecom: Failure to respond to CPR within 24 hours 2005762 ASSIGNED Tsung-Min Kuo [ca-compliance] [policy-failure] 2025-12-26T02:50:03Z 2025-12-12T15:10:14Z
D-Trust: CRL URL Disclosure 2007116 ASSIGNED Ana Laura Martorano [ca-compliance] [disclosure-failure] 2025-12-19T15:02:26Z 2025-12-19T14:22:17Z
DigiCert: Some certificates issued with CRLDPs that don’t exactly match CCADB disclosures 2007219 ASSIGNED DigiCert [ca-compliance] [disclosure failure] 2025-12-22T18:06:11Z 2025-12-20T00:36:17Z
Disig: Missing CA Disig R2I2 Certification Service Full CRL URLs in CCADB 2007066 ASSIGNED Peter Miskovic [ca-compliance] [disclosure-failure] 2025-12-19T17:23:58Z 2025-12-19T07:40:20Z
eMudhra emSign PKI Services: CRL URL Mismatch Between CCADB Disclosure and Issued Certificates 2007297 ASSIGNED Naveen Kumar ML [ca-compliance] [disclosure failure] 2025-12-22T17:36:11Z 2025-12-21T12:56:39Z
Financijska agencija (Fina): Mis-issued certificates 1986968 ASSIGNED miroslav.perincic [ca-compliance] [dv-misissuance] 2025-12-24T07:09:01Z 2025-09-04T16:47:06Z
GlobalSign: misalignment of CRL URL in CCADB with issued certificates 2007098 ASSIGNED Christophe Bonjean [ca-compliance] [disclosure-failure] 2025-12-19T15:10:19Z 2025-12-19T13:00:22Z
GoDaddy: CA Certificates Published in PEM format 2004845 ASSIGNED Steven Deitte [ca-compliance] [policy-failure] 2025-12-22T20:33:14Z 2025-12-09T01:00:32Z
GoDaddy: CRL Disclosure in CCADB Mismatch with Issued Certificates 2007216 ASSIGNED Steven Deitte [ca-compliance] [disclosure failure] 2025-12-22T18:08:12Z 2025-12-20T00:13:07Z
GoDaddy: Missing R1 Intermediate Full CRL URLs in CCADB 2002402 ASSIGNED Steven Deitte [close on 2025-12-24] [ca-compliance] [disclosure-failure] 2025-12-18T17:50:35Z 2025-11-25T21:22:15Z
GoDaddy: Partitioned CRL files missing Issuing Distribution Point 2007217 ASSIGNED Steven Deitte [ca-compliance] [disclosure failure] 2025-12-22T18:07:08Z 2025-12-20T00:15:11Z
IdenTrust: CA Certificate not published in DER Encoded Format 2004492 ASSIGNED IdenTrust [ca-compliance] [policy-failure] 2025-12-20T01:11:39Z 2025-12-05T23:02:09Z
IdenTrust: TLS self audit testing below 3% 1991558 ASSIGNED IdenTrust [ca-compliance] [policy-failure] Next update 2026-01-02 2025-12-16T15:19:46Z 2025-09-29T23:04:25Z
Microsoft PKI Services: End Entity Certificate Mis-issuance against CPS (BasicConstraints) 1979475 ASSIGNED Microsoft PKI Services [ca-compliance] [policy-failure] [ov-misissuance] 2025-12-20T00:18:58Z 2025-07-26T00:21:43Z
Microsoft PKI Services: Improper Disclosure of CRL 2007221 ASSIGNED Microsoft PKI Services [ca-compliance] [disclosure failure] 2025-12-22T18:05:22Z 2025-12-20T00:39:37Z
Microsoft PKI Services: Policy document bug 1962829 ASSIGNED Microsoft PKI Services [ca-compliance] [policy-failure] 2025-12-20T00:21:40Z 2025-04-26T02:10:29Z
Microsoft PKI Services: OCSP Non-Compliance 1999850 ASSIGNED Microsoft PKI Services [ca-compliance] [ocsp-failure] 2025-12-20T00:18:17Z 2025-11-13T01:29:14Z
NAVER Cloud Trust Services: CA Certificate not published in DER Encoded Format 2004733 ASSIGNED Hogeun Yoo [ca-compliance] [policy-failure] 2025-12-19T07:45:15Z 2025-12-08T16:04:05Z
NAVER Cloud Trust Services: Failure to respond to CPR within 24 hours 2004698 ASSIGNED Hogeun Yoo [ca-compliance] [policy-failure] [external] 2025-12-18T08:27:24Z 2025-12-08T13:49:22Z
Netlock: CA in AIA in PEM format 2004699 ASSIGNED Roland [ca-compliance] [policy-failure] 2025-12-08T15:50:05Z 2025-12-08T13:50:23Z
NETLOCK: Missing CDP Disclosure in CCADB 2001327 ASSIGNED Roland [ca-compliance] [disclosure-failure] 2025-12-22T20:07:06Z 2025-11-20T13:48:14Z
PKIoverheid: TSP Cleverbase Findings in 2025 ETSI Audit - Incident Report #1 – Incorrect issuer CA listed in CPS 1985816 ASSIGNED Policy Authority PKIoverheid [ca-compliance] [audit-finding] 2025-12-23T15:10:49Z 2025-08-28T15:39:28Z
PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #10 – Firewall Rules and Review 1983270 ASSIGNED Policy Authority PKIoverheid [ca-compliance] [audit-finding] 2025-12-23T13:14:12Z 2025-08-15T14:12:58Z
PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #11 – Anti-Malware Software 1983271 ASSIGNED Policy Authority PKIoverheid [ca-compliance] [audit-finding] 2025-12-23T15:23:33Z 2025-08-15T14:14:13Z
PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #3 – Internal Audit 1983263 ASSIGNED Policy Authority PKIoverheid [ca-compliance] [audit-finding] 2025-12-23T14:38:56Z 2025-08-15T14:05:23Z
PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #7 – Change Management 1983267 ASSIGNED Policy Authority PKIoverheid [ca-compliance] [audit-finding] 2025-12-23T14:45:03Z 2025-08-15T14:09:40Z
PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #9 – Lifecycle Management 1983269 ASSIGNED Policy Authority PKIoverheid [ca-compliance] [audit-finding] 2025-12-23T14:45:48Z 2025-08-15T14:11:31Z
SECOM: Invalid stateOrProvinceName 2004654 ASSIGNED SECOM Trust Systems - ONO Fumiaki [ca-compliance] [ov-misissuance] 2025-12-24T09:38:08Z 2025-12-08T10:09:35Z
SECOM: Non conformant SCT Encoding Due to SCT Modification by Cybertrust Japan (CTJ) 2007070 ASSIGNED SECOM Trust Systems - ONO Fumiaki [ca-compliance] [ov-misissuance] 2025-12-19T15:16:00Z 2025-12-19T08:01:55Z
SHECA: CA Certificate not published in DER Encoded Format 2005149 ASSIGNED SHECA [ca-compliance] [policy-failure] 2025-12-22T21:19:07Z 2025-12-10T08:19:34Z
SHECA: subordinate certificates have not published the complete CRL address in CCADB 2007089 ASSIGNED SHECA [ca-compliance] [disclosure-failure] 2025-12-19T15:11:28Z 2025-12-19T11:06:11Z
SHECA: TLS certificate key generation online 1993357 ASSIGNED SHECA [ca-compliance] [dv-misissuance] [ov-misissuance] 2025-12-24T11:24:26Z 2025-10-08T19:46:26Z
SwissSign: recommendation on backup testing 1990272 ASSIGNED Sandy Balzer [ca-compliance] [audit-finding] Next update 2026-04-30 2025-10-28T12:52:09Z 2025-09-23T17:06:29Z
SwissSign: recommendation on BIA/BCP review 1990263 ASSIGNED Sandy Balzer [ca-compliance] [audit-finding] Next update 2026-04-30 2025-10-28T12:51:27Z 2025-09-23T16:53:15Z
SwissSign: recommendation on BIA/BCP test coverage 1990266 ASSIGNED Sandy Balzer [ca-compliance] [audit-finding] Next update 2026-04-30 2025-10-28T12:51:38Z 2025-09-23T16:55:40Z
SwissSign: recommendation on CA-specific risk assessment 1990277 ASSIGNED Sandy Balzer [ca-compliance] [audit-finding] Next update 2026-04-30 2025-10-28T12:52:51Z 2025-09-23T17:08:41Z
SwissSign: recommendation on document release dual control 1990269 ASSIGNED Sandy Balzer [ca-compliance] [audit-finding] Next update 2026-04-30 2025-10-28T12:51:48Z 2025-09-23T17:03:05Z
SwissSign: recommendation on evaluation of cloud service providers 1990276 ASSIGNED Sandy Balzer [ca-compliance] [audit-finding] Next update 2026-04-30 2025-10-28T12:52:39Z 2025-09-23T17:08:11Z
SwissSign: recommendation on firewall review 1990271 ASSIGNED Sandy Balzer [ca-compliance] [audit-finding] Next update 2026-04-30 2025-10-28T12:51:54Z 2025-09-23T17:05:31Z
SwissSign: recommendation on linting software updates 1990282 ASSIGNED Sandy Balzer [ca-compliance] [audit-finding] Next update 2026-04-30 2025-11-03T08:50:16Z 2025-09-23T17:12:55Z
SwissSign: recommendation on log review process 1990285 ASSIGNED Sandy Balzer [ca-compliance] [audit-finding] Next update 2026-04-30 2025-10-28T12:54:20Z 2025-09-23T17:14:00Z
SwissSign: recommendation on publication process for CA related data 1990275 ASSIGNED Sandy Balzer [ca-compliance] [audit-finding] Next update 2026-04-30 2025-10-28T12:52:27Z 2025-09-23T17:07:40Z
SwissSign: recommendation on review of key pair generation implementation 1990284 ASSIGNED Sandy Balzer [ca-compliance] [audit-finding] Next update 2026-04-30 2025-10-28T12:53:56Z 2025-09-23T17:13:29Z
SwissSign: recommendation on risk assessment 1990254 ASSIGNED Sandy Balzer [ca-compliance] [audit-finding] Next update 2026-04-30 2025-10-28T12:50:25Z 2025-09-23T16:08:48Z
SwissSign: recommendation on self-assessment tool 1990281 ASSIGNED Sandy Balzer [ca-compliance] [audit-finding] Next update 2026-04-30 2025-10-28T12:53:00Z 2025-09-23T17:12:19Z
SwissSign: recommendation on synchronization of staging and production environments 1990274 ASSIGNED Sandy Balzer [ca-compliance] [audit-finding] Next update 2026-04-30 2025-10-28T12:52:18Z 2025-09-23T17:07:10Z
Telekom Security: Root-CA certificates published in PEM encoded format 2004668 ASSIGNED Stefan Kirch [ca-compliance] [policy-failure] 2025-12-24T08:49:41Z 2025-12-08T10:56:05Z
Telia: Findings in 2025 ETSI Audit - Incident Report #1 – Vulnerability management 1999296 ASSIGNED Antti Backman [close on 2025-12-29] [ca-compliance] [audit-finding] 2025-12-22T17:40:29Z 2025-11-10T15:09:58Z
TrustAsia: CRL disclosure address incorrectly using HTTPS scheme in CCADB 2007072 ASSIGNED TrustAsia [ca-compliance] [disclosure-failure] 2025-12-19T15:13:16Z 2025-12-19T08:16:36Z
TWCA: CA Certificate not published in DER Encoded Format 2004521 ASSIGNED chtsai [ca-compliance] [policy-failure] Next update 2026-01-15 2025-12-18T02:59:29Z 2025-12-06T06:30:14Z

59 Total; 59 Open (100%); 0 Resolved (0%); 0 Verified (0%);


Audit Delays

The compliance bug's whiteboard field is tagged with [audit-delay] whenever a CA is unable to deliver audit statements to Mozilla when they are due. Such bugs should be reported as CA compliance issues, with the following whiteboard tags as described here.

  • Whiteboard = [ca-compliance][audit-delay]
  • For audit delays due to mandated restrictions regarding COVID-19, use Whiteboard = [ca-compliance][audit-delay][covid-19]

No results.

0 Total; 0 Open (0%); 0 Resolved (0%); 0 Verified (0%);


Revocation Delays

The compliance bug's whiteboard field is tagged with [ca-revocation-delay] or [leaf-revocation-delay] whenever a CA fails to abide by Mozilla's requirement to revoke certificates in a timely fashion. As discussed in CA/Responding_To_An_Incident#Revocation, Mozilla recognizes that there may be *exceptional* situations that cause a CA to not abide by the Baseline Requirements, which should be accompanied by an Incident Report.

Such bugs should be reported as CA compliance issues, and will be categorized appropriately during triage.

Full Query
Summary ID Status Assigned to Whiteboard Last change time Creation time
[meta] Delayed Revocation 1911183 ASSIGNED Ben Wilson [ca-compliance] [meta] [leaf-revocation-delay] 2025-06-10T20:05:50Z 2024-08-01T20:05:04Z
Microsoft PKI Services: Failure to Revoke in 5 Days for 1962829 1965612 ASSIGNED Microsoft PKI Services [ca-compliance] [leaf-revocation-delay] 2025-12-24T18:22:06Z 2025-05-10T01:34:01Z
SHECA: Delayed revocation of TLS certificates affected by bug #1993357 1994051 ASSIGNED SHECA [ca-compliance] [leaf-revocation-delay] Next update 2025-12-31 2025-12-11T14:14:50Z 2025-10-13T18:23:58Z
VikingCloud: Delayed revocation of TLS certificates in connection to bug #1883779 1885568 ASSIGNED VikingCloud CA [close on 2025-12-29] [ca-compliance] [ov-misissuance] [leaf-revocation-delay] 2025-12-22T18:13:57Z 2024-03-15T16:20:17Z

4 Total; 4 Open (100%); 0 Resolved (0%); 0 Verified (0%);


Closed CA Bugs

Closed CA Compliance Bugs

A historical view of past CA compliance bugs may be found here: