CA/PKI Weekly Digest - Aug 24 - Aug 31, 2026
Stay alert of the changes for your SSL/TLS cert
TLS Radar continuously monitors every certificate across your domains and alerts you weeks before anything expires, and also catches the silent failure modes - chain breaks, weak ciphers, hostname mismatches, risky EKUs, and distrust events - that keep a site from opening in every browser. Built for solo developers monitoring a handful of sites and for enterprise teams managing thousands of certificates across multiple environments.
A weekly summary of certificate authority incidents and compliance activity, sourced from Mozilla's public CA Program tracker.
New this week
- Microsec: Insufficent support for "unspecified (0)" revocation reason - source
- Microsoft PKI Services: Missed Seven-Day Update for Bugzilla 2059818 - source
- SECOM: Inaccurate CP/CPS description regarding the basicConstraints extension of OCSP responder certificates by Cybertrust Japan (CTJ) - source
- Actalis: Incorrect CRL Distribution Point in TLS Server Certificates - source
- IdenTrust: 2026 Audit Report Finding - source
- CFCA: Cross-signed certificate missing the Extended Key Usage (EKU) extension - source
- eMudhra emSign PKI Services: Test Website TLS Certificates Issued Against CP/CPS. - source
- SSL.com: Delayed disclosure of Timestamping CA in CCADB - source
- GoDaddy: CCADB Missing Partitioned CRL URL Disclosure - source
Updates on open incidents
- SDAIA: Delayed Revocation related to Bugzilla #2056942 - source
- SwissSign: Delayed revocation in Bug 2057448 - source
- ACCV: Delayed revocation related to Bugzilla #2061746 - source
- Asseco DS / Certum: Delayed publication of Full Incident Report for Bug 2055775 - source
- Firmaprofesional: Chrome Root Progam Policy - Dedicated TLS hierarchy / EKU requirements - source
- Asseco DS / Certum: Incomplete CRL Disclosure in CCADB - source
- HARICA: Issuance of Server TLS Certificates with id-kp-clientAuth KeyPurposeID against CP/CPS - source
- SHECA: Failed to provide a preliminary incident report within 72 hours - source
- SHECA: Disclosure alerts indicating audit information missing for 2 Sub-CAs - source
- CFCA: Incorrect countryName values in OV subscriber certificates - source
- CFCA: Delayed response to CPR related with bug 2058918 - source
- eMudhra emSign PKI Services: Invalid Subject Locality/State Values - source
- eMudhra emSign PKI Services: www Subdomain Inclusion in Certificate SAN via ACME Issuance Workflow - source
- iTrusChina: Inconsistent EKUs in CP/CPS and Mis-issuance of TLS Certificates with clientAuth against CP/CPS - source
- SDAIA: Missing S/MIME WebTrust audit coverage - source
- NETLOCK: Failure to Respond to a Certificate Problem Report Within 24 Hours - source
- D-Trust: Missing Pre-Signing Linting for TLS Issuance - source
- D-Trust: Missing Pre-Sign Linting for S/MIME Issuing CAs - source
- Microsoft PKI Services: Third-Party Code Signing CPS missed annual update and four Issuing CAs - source
- SSL.com: Invalid Subject stateOrProvince Values - source
- SSL.com: Failure to respond to Certificate Problem Report within 24 hours - source
- Certainly: Missing audit log entries for certificates issued during capacity testing - source
- Certainly: Test Website Certificate Renewal Failure Following Production Deployment Drift - source
- GlobalSign: StateOrProvince and LocalityName value inconsistency - source
- SSL.com: Invalid combinations of countryName, stateOrProvinceName, and localityName attributes - source
- Actalis: Issuance of Server TLS Certificates with id-kp-clientAuth against CPS - source
- Asseco DS / Certum: Incorrect Country in certificate - source
- SECOM: Missing Prior Notification and Approval for a Cross-Certificate Extending Trust to Externally-Operated JPRS CAs - source
- GlobalSign: Unicode replacement character issue in Subject - source
- Exploring the interaction between descriptive and normative language in CP/CPS documents and the potential for confusion - source
- Firmaprofesional: Delayed publication of 2026 Audit Attestation Letters - source
- FNMT: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy - source
- Amazon Trust Services: CP/CPS missing explicit adherence to latest version of policies - source
- D-Trust: CRL URL Disclosure - source
- Google Trust Services: CPS Missing root program attestation - source
- Disig: CP/CPS misstatement regarding Key Usage criticality for TLS certificates - source
- Sectigo: jurisdictionCountry versus organizationIdentifier mismatch in QWAC - source
- DigiCert: jurisdictionCountry in EV certificate - source
- D-TRUST: Incomplete Disclosure of CRL URLs - source
- ACCV: Issuance of Server TLS Certificates with CP/CPS Discrepancies - source
- Actalis: failure to timely update CP/CPS for AgID SubCAs - source
- Actalis: Undisclosed Subordinate CA Certificate - source
- GlobalSign: SubCA created with incorrect CPS Policy OID - source
- HARICA: TLS server certificate issuance against CP/CPS - source
- Sectigo: Incorrect jurisdictionStateOrProvinceName attribute value in Code Signing certificate - source
- SwissSign: Invalid Entry in State field - source
- SwissSign: Potential error in stateOrProvinceName - source
- Firmaprofesional: Chrome Root Program Policy - Incorrect CCADB hierarchy associations - source
- Let's Encrypt: CPS missing root program attestation - source
Resolved this week
- DigiCert: Blank SubCA Owner field in CCADB for cross-certificate - source
- Sectigo: Refusal to produce validation evidence for DV certificate issued via cPanel/WebPros subordinate CA (www.TradingExpertView.com, 2024-03-07) - source
- BEIJING CERTIFICATE AUTHORITY Co., Ltd.: Delayed publication of Full Incident Report for Bug 2056489 - source
- BEIJING CERTIFICATE AUTHORITY Co., Ltd.: Failure to Respond to a Certificate Problem Report Within 24 Hours - source
Get this digest in your inbox
Subscribe to receive this digest by email.