CA/Incident Dashboard

From MozillaWiki
< CA(Redirected from CA/ca-bugs)
Jump to navigation Jump to search

Open CA Bugs in Bugzilla

There are three separate lists of open compliance bugs below:

  • Compliance bugs (not including audit delays or leaf revocation delays)
  • Audit Delays
  • Leaf Revocation Delays

Open CA Compliance Bugs

A CA compliance bug relates to a concern about a CA's certificates failing to comply with Mozilla's CA Certificate Policy and/or a CA/Browser Forum requirement, and is determined to not be an imminent security concern. A CA's response to a CA compliance bug includes providing an Incident Report in the bug.

Anyone may create a CA Compliance bug as follows:

Full Query
Summary ID Status Assigned to Whiteboard Last change time Creation time
eMudhra emSign PKI Services : Delayed Publication of Issuing CA Certificates in CCADB 1999241 ASSIGNED Naveen Kumar ML [ca-compliance] [disclosure-failure] 2025-11-21T16:03:08Z 2025-11-10T12:27:27Z
Financijska agencija (Fina): Mis-issued certificates 1986968 ASSIGNED miroslav.perincic [ca-compliance] [dv-misissuance] 2025-11-10T12:32:58Z 2025-09-04T16:47:06Z
IdenTrust: TLS self audit testing below 3% 1991558 ASSIGNED IdenTrust [ca-compliance] [policy-failure] 2025-11-21T17:17:16Z 2025-09-29T23:04:25Z
IZENPE: not allowed Key Usage in ocsp responder certificate 1996857 ASSIGNED David [ca-compliance] [ocsp-failure] 2025-11-21T17:17:40Z 2025-10-28T16:09:31Z
Microsoft PKI Services: End Entity Certificate Mis-issuance against CPS (BasicConstraints) 1979475 ASSIGNED Microsoft PKI Services [ca-compliance] [policy-failure] [ov-misissuance] 2025-11-21T20:50:27Z 2025-07-26T00:21:43Z
Microsoft PKI Services: Policy document bug 1962829 ASSIGNED Microsoft PKI Services [ca-compliance] [policy-failure] 2025-11-21T20:49:53Z 2025-04-26T02:10:29Z
Microsoft PKI Services: OCSP Non-Compliance 1999850 ASSIGNED Microsoft PKI Services [ca-compliance] [ocsp-failure] 2025-11-13T15:44:08Z 2025-11-13T01:29:14Z
NETLOCK: Missing CDP Disclosure in CCADB 2001327 ASSIGNED Roland [ca-compliance] [disclosure-failure] 2025-11-21T15:45:40Z 2025-11-20T13:48:14Z
PKIoverheid: TSP Cleverbase Findings in 2025 ETSI Audit - Incident Report #1 – Incorrect issuer CA listed in CPS 1985816 ASSIGNED Policy Authority PKIoverheid [ca-compliance] [audit-finding] 2025-11-11T15:27:18Z 2025-08-28T15:39:28Z
PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #10 – Firewall Rules and Review 1983270 ASSIGNED Policy Authority PKIoverheid [ca-compliance] [audit-finding] 2025-10-09T16:06:55Z 2025-08-15T14:12:58Z
PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #11 – Anti-Malware Software 1983271 ASSIGNED Policy Authority PKIoverheid [ca-compliance] [audit-finding] 2025-10-28T15:24:58Z 2025-08-15T14:14:13Z
PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #15 – Outdated Software 1983275 ASSIGNED Policy Authority PKIoverheid [ca-compliance] [audit-finding] 2025-10-30T16:52:06Z 2025-08-15T14:18:19Z
PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #3 – Internal Audit 1983263 ASSIGNED Policy Authority PKIoverheid [ca-compliance] [audit-finding] 2025-10-28T15:10:22Z 2025-08-15T14:05:23Z
PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #7 – Change Management 1983267 ASSIGNED Policy Authority PKIoverheid [ca-compliance] [audit-finding] 2025-10-28T15:18:08Z 2025-08-15T14:09:40Z
PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #9 – Lifecycle Management 1983269 ASSIGNED Policy Authority PKIoverheid [ca-compliance] [audit-finding] 2025-10-28T15:20:33Z 2025-08-15T14:11:31Z
Sectigo: Certificate issuance by non-compliant Extant S/MIME CA 2000277 ASSIGNED Martijn Katerbarg [ca-compliance] [smime-misissuance] 2025-11-17T16:03:32Z 2025-11-14T18:04:01Z
Sectigo: Failure to reply to Certificate Problem Reports within 24 hours 1994454 ASSIGNED Martijn Katerbarg [ca-compliance] [policy-failure] Next update 2025-11-30 2025-10-31T15:48:21Z 2025-10-15T15:41:07Z
SHECA: TLS certificate key generation online 1993357 ASSIGNED SHECA [ca-compliance] [dv-misissuance] [ov-misissuance] 2025-11-21T17:16:51Z 2025-10-08T19:46:26Z
SwissSign: Attribute Change process did not revoke single-domain certificates 1995252 ASSIGNED Sandy Balzer [ca-compliance] Next update 2026-04-30 2025-11-20T13:15:08Z 2025-10-20T09:41:46Z
SwissSign: recommendation on backup testing 1990272 ASSIGNED Sandy Balzer [ca-compliance] [audit-finding] Next update 2026-04-30 2025-10-28T12:52:09Z 2025-09-23T17:06:29Z
SwissSign: recommendation on BIA/BCP review 1990263 ASSIGNED Sandy Balzer [ca-compliance] [audit-finding] Next update 2026-04-30 2025-10-28T12:51:27Z 2025-09-23T16:53:15Z
SwissSign: recommendation on BIA/BCP test coverage 1990266 ASSIGNED Sandy Balzer [ca-compliance] [audit-finding] Next update 2026-04-30 2025-10-28T12:51:38Z 2025-09-23T16:55:40Z
SwissSign: recommendation on CA-specific risk assessment 1990277 ASSIGNED Sandy Balzer [ca-compliance] [audit-finding] Next update 2026-04-30 2025-10-28T12:52:51Z 2025-09-23T17:08:41Z
SwissSign: recommendation on document release dual control 1990269 ASSIGNED Sandy Balzer [ca-compliance] [audit-finding] Next update 2026-04-30 2025-10-28T12:51:48Z 2025-09-23T17:03:05Z
SwissSign: recommendation on evaluation of cloud service providers 1990276 ASSIGNED Sandy Balzer [ca-compliance] [audit-finding] Next update 2026-04-30 2025-10-28T12:52:39Z 2025-09-23T17:08:11Z
SwissSign: recommendation on firewall review 1990271 ASSIGNED Sandy Balzer [ca-compliance] [audit-finding] Next update 2026-04-30 2025-10-28T12:51:54Z 2025-09-23T17:05:31Z
SwissSign: recommendation on linting software updates 1990282 ASSIGNED Sandy Balzer [ca-compliance] [audit-finding] Next update 2026-04-30 2025-11-03T08:50:16Z 2025-09-23T17:12:55Z
SwissSign: recommendation on log review process 1990285 ASSIGNED Sandy Balzer [ca-compliance] [audit-finding] Next update 2026-04-30 2025-10-28T12:54:20Z 2025-09-23T17:14:00Z
SwissSign: recommendation on publication process for CA related data 1990275 ASSIGNED Sandy Balzer [ca-compliance] [audit-finding] Next update 2026-04-30 2025-10-28T12:52:27Z 2025-09-23T17:07:40Z
SwissSign: recommendation on review of key pair generation implementation 1990284 ASSIGNED Sandy Balzer [ca-compliance] [audit-finding] Next update 2026-04-30 2025-10-28T12:53:56Z 2025-09-23T17:13:29Z
SwissSign: recommendation on risk assessment 1990254 ASSIGNED Sandy Balzer [ca-compliance] [audit-finding] Next update 2026-04-30 2025-10-28T12:50:25Z 2025-09-23T16:08:48Z
SwissSign: recommendation on self-assessment tool 1990281 ASSIGNED Sandy Balzer [ca-compliance] [audit-finding] Next update 2026-04-30 2025-10-28T12:53:00Z 2025-09-23T17:12:19Z
SwissSign: recommendation on synchronization of staging and production environments 1990274 ASSIGNED Sandy Balzer [ca-compliance] [audit-finding] Next update 2026-04-30 2025-10-28T12:52:18Z 2025-09-23T17:07:10Z
Telia: Findings in 2025 ETSI Audit - Incident Report #1 – Vulnerability management 1999296 ASSIGNED Antti Backman [ca-compliance] [audit-finding] 2025-11-21T17:16:42Z 2025-11-10T15:09:58Z

34 Total; 34 Open (100%); 0 Resolved (0%); 0 Verified (0%);


Audit Delays

The compliance bug's whiteboard field is tagged with [audit-delay] whenever a CA is unable to deliver audit statements to Mozilla when they are due. Such bugs should be reported as CA compliance issues, with the following whiteboard tags as described here.

  • Whiteboard = [ca-compliance][audit-delay]
  • For audit delays due to mandated restrictions regarding COVID-19, use Whiteboard = [ca-compliance][audit-delay][covid-19]

No results.

0 Total; 0 Open (0%); 0 Resolved (0%); 0 Verified (0%);


Revocation Delays

The compliance bug's whiteboard field is tagged with [ca-revocation-delay] or [leaf-revocation-delay] whenever a CA fails to abide by Mozilla's requirement to revoke certificates in a timely fashion. As discussed in CA/Responding_To_An_Incident#Revocation, Mozilla recognizes that there may be *exceptional* situations that cause a CA to not abide by the Baseline Requirements, which should be accompanied by an Incident Report.

Such bugs should be reported as CA compliance issues, and will be categorized appropriately during triage.

Full Query
Summary ID Status Assigned to Whiteboard Last change time Creation time
[meta] Delayed Revocation 1911183 ASSIGNED Ben Wilson [ca-compliance] [meta] [leaf-revocation-delay] 2025-06-10T20:05:50Z 2024-08-01T20:05:04Z
Microsoft PKI Services: Failure to Revoke in 5 Days for 1962829 1965612 ASSIGNED Microsoft PKI Services [ca-compliance] [leaf-revocation-delay] 2025-11-22T01:09:02Z 2025-05-10T01:34:01Z
SHECA: Delayed revocation of TLS certificates affected by bug #1993357 1994051 ASSIGNED SHECA [ca-compliance] [leaf-revocation-delay] 2025-11-21T17:16:33Z 2025-10-13T18:23:58Z
VikingCloud: Delayed revocation of TLS certificates in connection to bug #1883779 1885568 ASSIGNED VikingCloud CA [ca-compliance] [ov-misissuance] [leaf-revocation-delay] 2025-11-07T20:46:36Z 2024-03-15T16:20:17Z

4 Total; 4 Open (100%); 0 Resolved (0%); 0 Verified (0%);


Closed CA Bugs

Closed CA Compliance Bugs

A historical view of past CA compliance bugs may be found here: