Skip to main content

CA/PKI Weekly Digest - Aug 14 - Aug 21, 2026

Stay alert of the changes for your SSL/TLS cert

TLS Radar continuously monitors every certificate across your domains and alerts you weeks before anything expires, and also catches the silent failure modes - chain breaks, weak ciphers, hostname mismatches, risky EKUs, and distrust events - that keep a site from opening in every browser. Built for solo developers monitoring a handful of sites and for enterprise teams managing thousands of certificates across multiple environments.

A weekly summary of certificate authority incidents and compliance activity, sourced from Mozilla's public CA Program tracker.

New this week

  • ACCV: Delayed revocation related to Bugzilla #2061746 - source
  • IdenTrust: Expired certificates for "Revoked" test websites - source
  • SwissSign: Delayed revocation in Bug 2057448 - source
  • SSL.com: Invalid combinations of countryName, stateOrProvinceName, and localityName attributes - source
  • SwissSign: Potential error in stateOrProvinceName - source
  • NETLOCK: Failure to file a preliminary incident report within 72 hours (OCSP responder incident, Bug 2051459) - source
  • Amazon Trust Services: CP/CPS missing explicit adherence to latest version of policies - source

Updates on open incidents

  • SwissSign: Delayed revocation related to Bugzilla 2033000 - source
  • SDAIA: Delayed Revocation related to Bugzilla #2056942 - source
  • D-Trust: Missing Pre-Signing Linting for TLS Issuance - source
  • Let's Encrypt: Gen Y Cross-Certified Subordinate CAs missing serverAuth EKU - source
  • SSL.com: Failure to respond to Certificate Problem Report within 24 hours - source
  • SSL.com: Invalid Subject stateOrProvince Values - source
  • Firmaprofesional: Delayed publication of 2026 Audit Attestation Letters - source
  • GlobalSign: SubCA created with incorrect CPS Policy OID - source
  • HARICA: Issuance of Server TLS Certificates without AIA OCSP URI against CP/CPS - source
  • DigiCert: Blank SubCA Owner field in CCADB for cross-certificate - source
  • Asseco DS / Certum: Delayed publication of Full Incident Report for Bug 2055775 - source
  • HARICA: TLS server certificate issuance against CP/CPS - source
  • Actalis: Issuance of Server TLS Certificates with id-kp-clientAuth against CPS - source
  • D-TRUST: Incomplete Disclosure of CRL URLs - source
  • D-Trust: Missing Pre-Sign Linting for S/MIME Issuing CAs - source
  • D-Trust: CRL URL Disclosure - source
  • ACCV: Issuance of Server TLS Certificates with CP/CPS Discrepancies - source
  • Asseco DS / Certum: Incorrect Country in certificate - source
  • Disig: CP/CPS misstatement regarding Key Usage criticality for TLS certificates - source
  • Sectigo: Refusal to produce validation evidence for DV certificate issued via cPanel/WebPros subordinate CA (www.TradingExpertView.com, 2024-03-07) - source
  • Exploring the interaction between descriptive and normative language in CP/CPS documents and the potential for confusion - source
  • Sectigo: jurisdictionCountry versus organizationIdentifier mismatch in QWAC - source
  • FNMT: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy - source
  • eMudhra emSign PKI Services: Invalid Subject Locality/State Values - source
  • NETLOCK: OCSP Service Returning Error for Issued Certificate - source
  • DigiCert: jurisdictionCountry in EV certificate - source
  • Actalis: failure to timely update CP/CPS for AgID SubCAs - source
  • Actalis: Undisclosed Subordinate CA Certificate - source
  • SwissSign: Invalid Entry in State field - source
  • Firmaprofesional: Chrome Root Program Policy - Incorrect CCADB hierarchy associations - source
  • Sectigo: Incorrect jurisdictionStateOrProvinceName attribute value in Code Signing certificate - source
  • BEIJING CERTIFICATE AUTHORITY Co., Ltd.: Delayed publication of Full Incident Report for Bug 2056489 - source
  • BEIJING CERTIFICATE AUTHORITY Co., Ltd.: Failure to Respond to a Certificate Problem Report Within 24 Hours - source
  • SDAIA: Missing S/MIME WebTrust audit coverage - source
  • CFCA: Delayed response to CPR related with bug 2058918 - source
  • CFCA: Incorrect countryName values in OV subscriber certificates - source
  • iTrusChina: Inconsistent EKUs in CP/CPS and Mis-issuance of TLS Certificates with clientAuth against CP/CPS - source
  • Let's Encrypt: CPS missing root program attestation - source
  • HARICA: Issuance of Server TLS Certificates with id-kp-clientAuth KeyPurposeID against CP/CPS - source
  • Certainly: Missing audit log entries for certificates issued during capacity testing - source
  • Certainly: Test Website Certificate Renewal Failure Following Production Deployment Drift - source

Resolved this week

  • BEIJING CERTIFICATE AUTHORITY Co., Ltd.: Incident Report - TLS Certificates Issued with RSA Public Exponent 3 - source
  • Chunghwa Telecom: Incomplete disclosure of CRL URLs in CCADB - source
  • TunTrust: OCSP responder "Unknown" of one Pre-certificate - source
  • DigiCert: Delayed response to problem report related to Bug 2055539 - source
  • DigiCert: Incomplete disclosure of CRL URLs in CCADB - source
  • Apple: Audit Documents missing 2 Sub-CAs - source
  • CFCA: Delayed response to CPR-related email related with bug 2049179 - source
  • D-Trust: EV Subordinate CA missing required cabfOrganizationIdentifier extension - source

Get this digest in your inbox

Subscribe to receive this digest by email.