<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>certdesk — CA industry news</title><description>Daily digest of CA/Browser Forum posts and Mozilla CA incompliance cases</description><link>https://certdesk.dev/en/news/</link><item><title>NETLOCK Certificate Problem Report [CRL RFC 5280 S5.2.3]</title><link>https://bugzilla.mozilla.org/show_bug.cgi?id=2075720</link><guid isPermaLink="true">https://bugzilla.mozilla.org/show_bug.cgi?id=2075720</guid><description>NETLOCK reported an issue with the CRL of its root CA, NetLock Arany (Class Gold) Főtanúsítvány, where two different versions were served under the same cRLNumber (39), violating RFC 5280 §5.2.3 and CA/Browser Forum Baseline Requirements §7.2.2. NETLOCK is investigating the matter.</description><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><category>incident</category></item><item><title>Actalis: Incorrect Revocation dates in CRL entries</title><link>https://bugzilla.mozilla.org/show_bug.cgi?id=2075655</link><guid isPermaLink="true">https://bugzilla.mozilla.org/show_bug.cgi?id=2075655</guid><description>Actalis: Incorrect Revocation dates in CRL entries</description><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><category>incident</category></item><item><title>KIR: SZAFIR ROOT CA3 TLS CRL nextUpdate exceeds 12 months</title><link>https://bugzilla.mozilla.org/show_bug.cgi?id=2075606</link><guid isPermaLink="true">https://bugzilla.mozilla.org/show_bug.cgi?id=2075606</guid><description>KIR confirmed that the CRL issued by SZAFIR ROOT CA3 TLS had a nextUpdate value exceeding 12 months. The same issue was found in the CRL issued by SZAFIR ROOT CA5 SMIME. KIR issued new CRLs with corrected nextUpdate values, in compliance with the Baseline Requirements.</description><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><category>incident</category></item><item><title>Firmaprofesional: certificateHold reasonCode entries in AC Firmaprofesional - CUALIFICADOS CRL</title><link>https://bugzilla.mozilla.org/show_bug.cgi?id=2075527</link><guid isPermaLink="true">https://bugzilla.mozilla.org/show_bug.cgi?id=2075527</guid><description>Firmaprofesional received a report on September 23, 2026, identifying certificateHold reasonCode entries in the public CRL for AC Firmaprofesional - CUALIFICADOS. The company is investigating whether these entries constitute non-compliance with TLS Baseline Requirements §§ 4.9.13 and 7.2.2. The review includes an assessment of the CRLs and the affected certificates.</description><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><category>incident</category></item><item><title>Telia: CRL signature algorithm property non-conformance for EC issuer key</title><link>https://bugzilla.mozilla.org/show_bug.cgi?id=2075488</link><guid isPermaLink="true">https://bugzilla.mozilla.org/show_bug.cgi?id=2075488</guid><description>Telia&apos;s EC TLS DV CA v4 issued CRLs have a non-conformance issue with the signature algorithm property. The same issue was found in Telia EC TLS Root CA v3, Telia EC Email Root CA v3, Telia EC Client Root CA v3, and Telia EC Signing Root CA v3. The issue is due to an incorrect CA configuration setting.</description><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><category>incident</category></item><item><title>NETLOCK: Certificate Problem Report [CRL URL not disclosed in CCADB]</title><link>https://bugzilla.mozilla.org/show_bug.cgi?id=2075258</link><guid isPermaLink="true">https://bugzilla.mozilla.org/show_bug.cgi?id=2075258</guid><description>NETLOCK was reported for not disclosing CRL Distribution Point URLs in the CCADB for the corresponding issuing CA. The issue was reported by a third party and NETLOCK is investigating. According to CCADB Policy §6.2, CA Owners must disclose these URLs to the CCADB within 7 days of issuing the first certificate containing the URL or within 4 hours of revoking it.</description><pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate><category>incident</category></item><item><title>NETLOCK: Certificate Problem Report [CRL BR S7.2.2]</title><link>https://bugzilla.mozilla.org/show_bug.cgi?id=2075255</link><guid isPermaLink="true">https://bugzilla.mozilla.org/show_bug.cgi?id=2075255</guid><description>A third party reported that NETLOCK&apos;s issuing CAs&apos; CRLs contain entries with the reasonCode set to unspecified (0), violating CA/Browser Forum Baseline Requirements §7.2.2. NETLOCK has received the report and is investigating. A full incident report will follow.</description><pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate><category>incident</category></item><item><title>Amazon Trust Services – CP/CPS for externally operated subordinate CAs not updated in CCADB within 14 days</title><link>https://bugzilla.mozilla.org/show_bug.cgi?id=2075247</link><guid isPermaLink="true">https://bugzilla.mozilla.org/show_bug.cgi?id=2075247</guid><description>Amazon Trust Services – CP/CPS for externally operated subordinate CAs not updated in CCADB within 14 days</description><pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate><category>incident</category></item><item><title>Asseco DS / Certum: Incorrect ECDSA-SHA384 AlgorithmIdentifier Encoding in CRLs</title><link>https://bugzilla.mozilla.org/show_bug.cgi?id=2075242</link><guid isPermaLink="true">https://bugzilla.mozilla.org/show_bug.cgi?id=2075242</guid><description>Certum found 15 CRLs with incorrect ECDSA-SHA384 AlgorithmIdentifier encoding on 2026-09-23. The issue affects CRLs generated by Certum and violates the CA/Browser Forum Baseline Requirements and RFC 5758. The affected CRLs have been identified by Certum.</description><pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate><category>incident</category></item><item><title>Asseco DS / Certum: CRL URLs in issued certificates not disclosed in CCADB</title><link>https://bugzilla.mozilla.org/show_bug.cgi?id=2075234</link><guid isPermaLink="true">https://bugzilla.mozilla.org/show_bug.cgi?id=2075234</guid><description>Asseco DS / Certum: CRL URLs in issued certificates not disclosed in CCADB</description><pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate><category>incident</category></item><item><title>SSL.com: Failure to Post all Root and Intermediate CA certificates in Repository identified in CP/CPS</title><link>https://bugzilla.mozilla.org/show_bug.cgi?id=2074980</link><guid isPermaLink="true">https://bugzilla.mozilla.org/show_bug.cgi?id=2074980</guid><description>SSL.com&apos;s external auditors found that the company failed to post all Root and Intermediate CA certificates in its repository as required by its CP/CPS. The CP/CPS states that all Root and Intermediate CA certificates used by the SSL.com PKI must be available in the repository. SSL.com is required to post the certificates in accordance with the Baseline Requirements and its CP/CPS.</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate><category>incident</category></item><item><title>Let&apos;s Encrypt: Root CRLs Missing Reason Code</title><link>https://bugzilla.mozilla.org/show_bug.cgi?id=2074944</link><guid isPermaLink="true">https://bugzilla.mozilla.org/show_bug.cgi?id=2074944</guid><description>Let&apos;s Encrypt revoked the Cross-Certified Subordinate CA Certificates of ISRG Root X2, Root YR, and Root YE with reason code &quot;superseded&quot;, but due to a bug in the ceremony tool, the reason code entry extension was omitted. Only two Root CRLs issued by ISRG Root X1 and ISRG Root X2 are impacted. The incident is contained since Root CRLs are only issued as part of manual ceremonies.</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate><category>incident</category></item><item><title>DigiCert:  EV JOI match with organizationIdentifer</title><link>https://bugzilla.mozilla.org/show_bug.cgi?id=2074611</link><guid isPermaLink="true">https://bugzilla.mozilla.org/show_bug.cgi?id=2074611</guid><description>DigiCert:  EV JOI match with organizationIdentifer</description><pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate><category>incident</category></item><item><title>SwissSign - Backdating of 48+h</title><link>https://bugzilla.mozilla.org/show_bug.cgi?id=2074466</link><guid isPermaLink="true">https://bugzilla.mozilla.org/show_bug.cgi?id=2074466</guid><description>SwissSign issued a TLS certificate with a notBefore value exceeding the maximum backdating period permitted by CA/Browser Forum Baseline Requirements 7.1.2.7. The certificate was signed on 2026-09-20 12:35:51 UTC with a notBefore value of 2026-09-18 11:57:03 UTC, resulting in a backdating interval of approximately 48 hours, 38 minutes, and 48 seconds. This exceeds the maximum permitted backdating period of 48 hours.</description><pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate><category>incident</category></item><item><title>PKIoverheid: TSP KPN Delayed publication of audit attestation letters in the CCADB</title><link>https://bugzilla.mozilla.org/show_bug.cgi?id=2074032</link><guid isPermaLink="true">https://bugzilla.mozilla.org/show_bug.cgi?id=2074032</guid><description>KPN PKIoverheid failed to upload the required Audit Attestation Letter to the CCADB for subCAs within the 92-day deadline, which expired on 2026-08-31. The letters were uploaded on 2026-09-10 and again on 2026-09-15. The relevant policies include CCADB Policy v2.1, Mozilla Root Store Policy v3.1, and Microsoft Trusted Root Certificate Program.</description><pubDate>Mon, 21 Sep 2026 00:00:00 GMT</pubDate><category>incident</category></item><item><title>Ballot SC104: Set presence of AIA extension to SHOULD for Subscriber Certificates</title><link>https://cabforum.org/2026/09/03/ballot-sc104-set-presence-of-aia-extension-to-should-for-subscriber-certificates/</link><guid isPermaLink="true">https://cabforum.org/2026/09/03/ballot-sc104-set-presence-of-aia-extension-to-should-for-subscriber-certificates/</guid><description>Ballot SC104 sets the presence of the AIA extension to SHOULD for Subscriber Certificates. The voting results showed a total of 21 votes. According to the Baseline Requirements, CAs must provide CRL and OCSP.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>ballot</category></item><item><title>Ballot SMC018: Realignment of Multipurpose use cases</title><link>https://cabforum.org/2026/08/11/ballot-smc-018/</link><guid isPermaLink="true">https://cabforum.org/2026/08/11/ballot-smc-018/</guid><description>The CA/Browser Forum is conducting a 30-day review period for Ballot SMC018: Realignment of Multipurpose use cases, which pertains to Final Maintenance Guidelines. The complete Draft Maintenance Guideline is available here. This review is being conducted pursuant to Section 4.1 of the CA/Browser Forum’s Intellectual Property Rights Policy (v1.4).</description><pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate><category>ballot</category></item><item><title>Ballot SC100: DNSSEC Clarification and Consolidation</title><link>https://cabforum.org/2026/08/06/ballot-sc100-dnssec-clarification-and-consolidation/</link><guid isPermaLink="true">https://cabforum.org/2026/08/06/ballot-sc100-dnssec-clarification-and-consolidation/</guid><description>Ballot SC100 clarifies and consolidates DNSSEC-related provisions. Certificate Issuers must follow the Baseline Requirements. The ballot was decided with 22 votes in total.</description><pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate><category>ballot</category></item><item><title>Ballot SC102: EV Domain Reuse and Validity Alignment</title><link>https://cabforum.org/2026/07/14/ballot-sc102-ev-domain-reuse-and-validity-alignment/</link><guid isPermaLink="true">https://cabforum.org/2026/07/14/ballot-sc102-ev-domain-reuse-and-validity-alignment/</guid><description>CAs voted on Ballot SC102, with a total of 19 votes. Ballot SC102 addresses EV Domain Reuse and Validity Alignment in the Baseline Requirements.</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>ballot</category></item><item><title>Ballot SC0101v2: Clarify Authorization Domain Names</title><link>https://cabforum.org/2026/07/01/ballot-sc0101v2-clarify-authorization-domain-names/</link><guid isPermaLink="true">https://cabforum.org/2026/07/01/ballot-sc0101v2-clarify-authorization-domain-names/</guid><description>The CA must specify Authorization Domain Names according to the Baseline Requirements. Ballot SC0101v2 is a vote to clarify Authorization Domain Names. There were a total of 27 votes.</description><pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate><category>ballot</category></item><item><title>Ballot CSC-32: Make a Reserved Policy OID mandatory</title><link>https://cabforum.org/2026/06/16/ballot-csc-32-make-a-reserved-policy-oid-mandatory/</link><guid isPermaLink="true">https://cabforum.org/2026/06/16/ballot-csc-32-make-a-reserved-policy-oid-mandatory/</guid><description>Ballot CSC-32 was adopted on November 17, 2025, and the new CSC BRs v3.10.0 have been published to the CABF public website. No IPR Exclusion Notices were filed. Ballot CSC-32 makes a Reserved Policy OID mandatory.</description><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><category>ballot</category></item><item><title>Ballot SMC017v2: Increase Minimum RSA CA Key Size</title><link>https://cabforum.org/2026/06/16/ballot-smc-017v2/</link><guid isPermaLink="true">https://cabforum.org/2026/06/16/ballot-smc-017v2/</guid><description>Ballot SMC017v2 increases the minimum RSA CA key size. The Intellectual Property Review period has been completed, and the ballot was adopted as of July 30, 2026. The new S/MIME BR v.1.0.15 has been published to the CABF public website.</description><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><category>ballot</category></item></channel></rss>