Mozilla Bugzilla / public incident reports

HARICA Revokes Hundreds of Thousands of Certificates Over Compliance Gaps

HARICA Revokes Hundreds of Thousands of Certificates Over Compliance Gaps

HARICA disclosed two separate certificate mis-issuance incidents in July, each requiring mass revocation under CA/Browser Forum rules. Together they affected several hundred thousand certificates — among the larger revocation events of the year.

Incident one: an outdated internal deadline

HARICA's own Certificate Policy document still referenced an old clientAuth EKU removal deadline of June 15, 2026, even after the Chrome Root Program had since moved the actual industry deadline out to March 2027. Because HARICA's internal policy document hadn't been updated to match, the CA kept including the clientAuth EKU in certificates issued after its own stated (if outdated) cutoff — technically compliant with Chrome's current policy, but in direct violation of HARICA's own published CP/CPS. Roughly 66,000 certificates were affected, with revocation completed within five days of the violation being confirmed.

Incident two: a missing extension

A second, larger incident followed close behind: HARICA had removed the OCSP responder URL (AIA extension) from its issued certificates at the end of March, as part of its own planned move away from OCSP — but its CP/CPS document still required that extension's presence, and hadn't been updated to reflect the change. Every certificate issued in the roughly four-month gap between the undocumented change and its correction was technically mis-issued against HARICA's own policy: north of 235,000 certificates, revoked in stages through late July.

The common thread: documentation drift, not a security breach

Neither incident involved a compromised key, a validation bypass, or any certificate issued to the wrong party — both were violations of HARICA's own written policy falling out of sync with what its issuance systems were actually doing. That distinction matters for severity, but not for consequence: the Baseline Requirements treat a mis-issued certificate as mis-issued regardless of whether anyone was actually harmed, and mass revocation followed both times regardless of intent. (If you've never had to actually revoke a certificate yourself, our guide to the process covers what that actually involves on a much smaller scale.)

The lesson other CAs are already drawing from it

Industry commentary following the incidents converged on a specific, actionable point: a CA's issuance profiles and its policy documents need one shared source of truth, not two separately maintained descriptions of the same thing that can quietly drift apart. Given how many separate deadline changes have moved during this year's broader wave of certificate policy updates, that's a lesson with real relevance well beyond HARICA alone.

This is our own summary and analysis of publicly reported news, written independently — not a reproduction of any single source's article. Where we reference a specific announcement, we link to it or name the organization directly.