CA Industry News

A daily digest of official CA/Browser Forum posts and public incompliance cases from the Mozilla CA Program. Summaries are auto-generated — always check the original source before acting on anything. Updated: 2026-09-26 · RSS

2026-09-25

INCIDENTopen

NETLOCK Certificate Problem Report [CRL RFC 5280 S5.2.3]

NETLOCK reported an issue with the CRL of its root CA, NetLock Arany (Class Gold) Főtanúsítvány, where two different versions were served under the same cRLNumber (39), violating RFC 5280 §5.2.3 and CA/Browser Forum Baseline Requirements §7.2.2. NETLOCK is investigating the matter.

Source: Mozilla CA Program (Bugzilla) · View original

INCIDENTopen

Actalis: Incorrect Revocation dates in CRL entries

Source: Mozilla CA Program (Bugzilla) · View original

INCIDENTopen

KIR: SZAFIR ROOT CA3 TLS CRL nextUpdate exceeds 12 months

KIR confirmed that the CRL issued by SZAFIR ROOT CA3 TLS had a nextUpdate value exceeding 12 months. The same issue was found in the CRL issued by SZAFIR ROOT CA5 SMIME. KIR issued new CRLs with corrected nextUpdate values, in compliance with the Baseline Requirements.

Source: Mozilla CA Program (Bugzilla) · View original

INCIDENTopen

Firmaprofesional: certificateHold reasonCode entries in AC Firmaprofesional - CUALIFICADOS CRL

Firmaprofesional received a report on September 23, 2026, identifying certificateHold reasonCode entries in the public CRL for AC Firmaprofesional - CUALIFICADOS. The company is investigating whether these entries constitute non-compliance with TLS Baseline Requirements §§ 4.9.13 and 7.2.2. The review includes an assessment of the CRLs and the affected certificates.

Source: Mozilla CA Program (Bugzilla) · View original

INCIDENTopen

Telia: CRL signature algorithm property non-conformance for EC issuer key

Telia's EC TLS DV CA v4 issued CRLs have a non-conformance issue with the signature algorithm property. The same issue was found in Telia EC TLS Root CA v3, Telia EC Email Root CA v3, Telia EC Client Root CA v3, and Telia EC Signing Root CA v3. The issue is due to an incorrect CA configuration setting.

Source: Mozilla CA Program (Bugzilla) · View original

2026-09-24

INCIDENTopen

NETLOCK: Certificate Problem Report [CRL URL not disclosed in CCADB]

NETLOCK was reported for not disclosing CRL Distribution Point URLs in the CCADB for the corresponding issuing CA. The issue was reported by a third party and NETLOCK is investigating. According to CCADB Policy §6.2, CA Owners must disclose these URLs to the CCADB within 7 days of issuing the first certificate containing the URL or within 4 hours of revoking it.

Source: Mozilla CA Program (Bugzilla) · View original

INCIDENTopen

NETLOCK: Certificate Problem Report [CRL BR S7.2.2]

A third party reported that NETLOCK's issuing CAs' CRLs contain entries with the reasonCode set to unspecified (0), violating CA/Browser Forum Baseline Requirements §7.2.2. NETLOCK has received the report and is investigating. A full incident report will follow.

Source: Mozilla CA Program (Bugzilla) · View original

INCIDENTopen

Amazon Trust Services – CP/CPS for externally operated subordinate CAs not updated in CCADB within 14 days

Source: Mozilla CA Program (Bugzilla) · View original

INCIDENTopen

Asseco DS / Certum: Incorrect ECDSA-SHA384 AlgorithmIdentifier Encoding in CRLs

Certum found 15 CRLs with incorrect ECDSA-SHA384 AlgorithmIdentifier encoding on 2026-09-23. The issue affects CRLs generated by Certum and violates the CA/Browser Forum Baseline Requirements and RFC 5758. The affected CRLs have been identified by Certum.

Source: Mozilla CA Program (Bugzilla) · View original

INCIDENTopen

Asseco DS / Certum: CRL URLs in issued certificates not disclosed in CCADB

Source: Mozilla CA Program (Bugzilla) · View original

2026-09-23

INCIDENTopen

SSL.com: Failure to Post all Root and Intermediate CA certificates in Repository identified in CP/CPS

SSL.com's external auditors found that the company failed to post all Root and Intermediate CA certificates in its repository as required by its CP/CPS. The CP/CPS states that all Root and Intermediate CA certificates used by the SSL.com PKI must be available in the repository. SSL.com is required to post the certificates in accordance with the Baseline Requirements and its CP/CPS.

Source: Mozilla CA Program (Bugzilla) · View original

INCIDENTopen

Let's Encrypt: Root CRLs Missing Reason Code

Let's Encrypt revoked the Cross-Certified Subordinate CA Certificates of ISRG Root X2, Root YR, and Root YE with reason code "superseded", but due to a bug in the ceremony tool, the reason code entry extension was omitted. Only two Root CRLs issued by ISRG Root X1 and ISRG Root X2 are impacted. The incident is contained since Root CRLs are only issued as part of manual ceremonies.

Source: Mozilla CA Program (Bugzilla) · View original

2026-09-22

INCIDENTopen

DigiCert: EV JOI match with organizationIdentifer

Source: Mozilla CA Program (Bugzilla) · View original

INCIDENTopen

SwissSign - Backdating of 48+h

SwissSign issued a TLS certificate with a notBefore value exceeding the maximum backdating period permitted by CA/Browser Forum Baseline Requirements 7.1.2.7. The certificate was signed on 2026-09-20 12:35:51 UTC with a notBefore value of 2026-09-18 11:57:03 UTC, resulting in a backdating interval of approximately 48 hours, 38 minutes, and 48 seconds. This exceeds the maximum permitted backdating period of 48 hours.

Source: Mozilla CA Program (Bugzilla) · View original

2026-09-21

INCIDENTopen

PKIoverheid: TSP KPN Delayed publication of audit attestation letters in the CCADB

KPN PKIoverheid failed to upload the required Audit Attestation Letter to the CCADB for subCAs within the 92-day deadline, which expired on 2026-08-31. The letters were uploaded on 2026-09-10 and again on 2026-09-15. The relevant policies include CCADB Policy v2.1, Mozilla Root Store Policy v3.1, and Microsoft Trusted Root Certificate Program.

Source: Mozilla CA Program (Bugzilla) · View original

2026-09-03

BALLOT

Ballot SC104: Set presence of AIA extension to SHOULD for Subscriber Certificates

Ballot SC104 sets the presence of the AIA extension to SHOULD for Subscriber Certificates. The voting results showed a total of 21 votes. According to the Baseline Requirements, CAs must provide CRL and OCSP.

Source: CA/Browser Forum · View original

2026-08-11

BALLOT

Ballot SMC018: Realignment of Multipurpose use cases

The CA/Browser Forum is conducting a 30-day review period for Ballot SMC018: Realignment of Multipurpose use cases, which pertains to Final Maintenance Guidelines. The complete Draft Maintenance Guideline is available here. This review is being conducted pursuant to Section 4.1 of the CA/Browser Forum’s Intellectual Property Rights Policy (v1.4).

Source: CA/Browser Forum · View original

2026-08-06

BALLOT

Ballot SC100: DNSSEC Clarification and Consolidation

Ballot SC100 clarifies and consolidates DNSSEC-related provisions. Certificate Issuers must follow the Baseline Requirements. The ballot was decided with 22 votes in total.

Source: CA/Browser Forum · View original

2026-07-14

BALLOT

Ballot SC102: EV Domain Reuse and Validity Alignment

CAs voted on Ballot SC102, with a total of 19 votes. Ballot SC102 addresses EV Domain Reuse and Validity Alignment in the Baseline Requirements.

Source: CA/Browser Forum · View original

2026-07-01

BALLOT

Ballot SC0101v2: Clarify Authorization Domain Names

The CA must specify Authorization Domain Names according to the Baseline Requirements. Ballot SC0101v2 is a vote to clarify Authorization Domain Names. There were a total of 27 votes.

Source: CA/Browser Forum · View original

2026-06-16

BALLOT

Ballot CSC-32: Make a Reserved Policy OID mandatory

Ballot CSC-32 was adopted on November 17, 2025, and the new CSC BRs v3.10.0 have been published to the CABF public website. No IPR Exclusion Notices were filed. Ballot CSC-32 makes a Reserved Policy OID mandatory.

Source: CA/Browser Forum · View original

BALLOT

Ballot SMC017v2: Increase Minimum RSA CA Key Size

Ballot SMC017v2 increases the minimum RSA CA key size. The Intellectual Property Review period has been completed, and the ballot was adopted as of July 30, 2026. The new S/MIME BR v.1.0.15 has been published to the CABF public website.

Source: CA/Browser Forum · View original