A daily digest of official CA/Browser Forum posts and public incompliance cases from the Mozilla CA Program. Summaries are auto-generated — always check the original source before acting on anything. Updated: 2026-09-26 · RSS
2026-09-25
INCIDENTopen
NETLOCK Certificate Problem Report [CRL RFC 5280 S5.2.3]
NETLOCK reported an issue with the CRL of its root CA, NetLock Arany (Class Gold) Főtanúsítvány, where two different versions were served under the same cRLNumber (39), violating RFC 5280 §5.2.3 and CA/Browser Forum Baseline Requirements §7.2.2. NETLOCK is investigating the matter.
Source: Mozilla CA Program (Bugzilla) · View original
INCIDENTopen
Actalis: Incorrect Revocation dates in CRL entries
Source: Mozilla CA Program (Bugzilla) · View original
INCIDENTopen
KIR: SZAFIR ROOT CA3 TLS CRL nextUpdate exceeds 12 months
KIR confirmed that the CRL issued by SZAFIR ROOT CA3 TLS had a nextUpdate value exceeding 12 months. The same issue was found in the CRL issued by SZAFIR ROOT CA5 SMIME. KIR issued new CRLs with corrected nextUpdate values, in compliance with the Baseline Requirements.
Source: Mozilla CA Program (Bugzilla) · View original
INCIDENTopen
Firmaprofesional: certificateHold reasonCode entries in AC Firmaprofesional - CUALIFICADOS CRL
Firmaprofesional received a report on September 23, 2026, identifying certificateHold reasonCode entries in the public CRL for AC Firmaprofesional - CUALIFICADOS. The company is investigating whether these entries constitute non-compliance with TLS Baseline Requirements §§ 4.9.13 and 7.2.2. The review includes an assessment of the CRLs and the affected certificates.
Source: Mozilla CA Program (Bugzilla) · View original
INCIDENTopen
Telia: CRL signature algorithm property non-conformance for EC issuer key
Telia's EC TLS DV CA v4 issued CRLs have a non-conformance issue with the signature algorithm property. The same issue was found in Telia EC TLS Root CA v3, Telia EC Email Root CA v3, Telia EC Client Root CA v3, and Telia EC Signing Root CA v3. The issue is due to an incorrect CA configuration setting.
Source: Mozilla CA Program (Bugzilla) · View original
2026-09-24
INCIDENTopen
NETLOCK: Certificate Problem Report [CRL URL not disclosed in CCADB]
NETLOCK was reported for not disclosing CRL Distribution Point URLs in the CCADB for the corresponding issuing CA. The issue was reported by a third party and NETLOCK is investigating. According to CCADB Policy §6.2, CA Owners must disclose these URLs to the CCADB within 7 days of issuing the first certificate containing the URL or within 4 hours of revoking it.
Source: Mozilla CA Program (Bugzilla) · View original
INCIDENTopen
NETLOCK: Certificate Problem Report [CRL BR S7.2.2]
A third party reported that NETLOCK's issuing CAs' CRLs contain entries with the reasonCode set to unspecified (0), violating CA/Browser Forum Baseline Requirements §7.2.2. NETLOCK has received the report and is investigating. A full incident report will follow.
Source: Mozilla CA Program (Bugzilla) · View original
INCIDENTopen
Amazon Trust Services – CP/CPS for externally operated subordinate CAs not updated in CCADB within 14 days
Source: Mozilla CA Program (Bugzilla) · View original
INCIDENTopen
Asseco DS / Certum: Incorrect ECDSA-SHA384 AlgorithmIdentifier Encoding in CRLs
Certum found 15 CRLs with incorrect ECDSA-SHA384 AlgorithmIdentifier encoding on 2026-09-23. The issue affects CRLs generated by Certum and violates the CA/Browser Forum Baseline Requirements and RFC 5758. The affected CRLs have been identified by Certum.
Source: Mozilla CA Program (Bugzilla) · View original
INCIDENTopen
Asseco DS / Certum: CRL URLs in issued certificates not disclosed in CCADB
Source: Mozilla CA Program (Bugzilla) · View original
2026-09-23
INCIDENTopen
SSL.com: Failure to Post all Root and Intermediate CA certificates in Repository identified in CP/CPS
SSL.com's external auditors found that the company failed to post all Root and Intermediate CA certificates in its repository as required by its CP/CPS. The CP/CPS states that all Root and Intermediate CA certificates used by the SSL.com PKI must be available in the repository. SSL.com is required to post the certificates in accordance with the Baseline Requirements and its CP/CPS.
Source: Mozilla CA Program (Bugzilla) · View original
INCIDENTopen
Let's Encrypt: Root CRLs Missing Reason Code
Let's Encrypt revoked the Cross-Certified Subordinate CA Certificates of ISRG Root X2, Root YR, and Root YE with reason code "superseded", but due to a bug in the ceremony tool, the reason code entry extension was omitted. Only two Root CRLs issued by ISRG Root X1 and ISRG Root X2 are impacted. The incident is contained since Root CRLs are only issued as part of manual ceremonies.
Source: Mozilla CA Program (Bugzilla) · View original
2026-06-16
BALLOT
Ballot CSC-32: Make a Reserved Policy OID mandatory
Ballot CSC-32 was adopted on November 17, 2025, and the new CSC BRs v3.10.0 have been published to the CABF public website. No IPR Exclusion Notices were filed. Ballot CSC-32 makes a Reserved Policy OID mandatory.
Source: CA/Browser Forum · View original
BALLOT
Ballot SMC017v2: Increase Minimum RSA CA Key Size
Ballot SMC017v2 increases the minimum RSA CA key size. The Intellectual Property Review period has been completed, and the ballot was adopted as of July 30, 2026. The new S/MIME BR v.1.0.15 has been published to the CABF public website.
Source: CA/Browser Forum · View original