Skip to main content

CA/PKI Weekly Digest - Aug 31 - Sep 7, 2026

Stay alert of the changes for your SSL/TLS cert

TLS Radar continuously monitors every certificate across your domains and alerts you weeks before anything expires, and also catches the silent failure modes - chain breaks, weak ciphers, hostname mismatches, risky EKUs, and distrust events - that keep a site from opening in every browser. Built for solo developers monitoring a handful of sites and for enterprise teams managing thousands of certificates across multiple environments.

A weekly summary of certificate authority incidents and compliance activity, sourced from Mozilla's public CA Program tracker.

New this week

  • Sectigo: No revocation after CP/CPS language involving extendedKeyUsage found to be subject to multiple interpretations - source
  • TWCA: CPR subject.countryName - source
  • DigiCert: CPR subject.countryName - source
  • SECOM: Five Subordinate CA Certificates Issued Without Apple Prior Approval for Cybertrust Japan (CTJ) - source
  • Sectigo: CP/CPS language involving extendedKeyUsage found to be subject to multiple interpretations - source
  • Firmaprofesional: CP/CPS missing Chrome Root Program and CCADB policy attestation - source
  • Chunghwa Telcom: Delay of 2025 WebTrust for CA Audit Reports seals for ePKI & HiPKI - source

Updates on open incidents

  • Let's Encrypt: CRLs Temporarily Missing Revoked Serials - source
  • IdenTrust: Expired certificates for "Revoked" test websites - source
  • SwissSign: Delayed revocation in Bug 2057448 - source
  • ACCV: Delayed revocation related to Bugzilla #2061746 - source
  • SDAIA: Delayed Revocation related to Bugzilla #2056942 - source
  • CFCA: Cross-signed certificate missing the Extended Key Usage (EKU) extension - source
  • GlobalSign: Unicode replacement character issue in Subject - source
  • eMudhra emSign PKI Services: www Subdomain Inclusion in Certificate SAN via ACME Issuance Workflow - source
  • Asseco DS / Certum: Incomplete CRL Disclosure in CCADB - source
  • eMudhra emSign PKI Services: Invalid Subject Locality/State Values - source
  • Firmaprofesional: Chrome Root Progam Policy - Dedicated TLS hierarchy / EKU requirements - source
  • Asseco DS / Certum: Delayed publication of Full Incident Report for Bug 2055775 - source
  • NETLOCK: Failure to Respond to a Certificate Problem Report Within 24 Hours - source
  • SHECA: Disclosure alerts indicating audit information missing for 2 Sub-CAs - source
  • SHECA: Failed to provide a preliminary incident report within 72 hours - source
  • iTrusChina: Inconsistent EKUs in CP/CPS and Mis-issuance of TLS Certificates with clientAuth against CP/CPS - source
  • CFCA: Incorrect countryName values in OV subscriber certificates - source
  • CFCA: Delayed response to CPR related with bug 2058918 - source
  • Amazon Trust Services: CP/CPS missing explicit adherence to latest version of policies - source
  • Certainly: Test Website Certificate Renewal Failure Following Production Deployment Drift - source
  • Disig: CP/CPS misstatement regarding Key Usage criticality for TLS certificates - source
  • Microsoft PKI Services: Missed Seven-Day Update for Bugzilla 2059818 - source
  • GoDaddy: CCADB Missing Partitioned CRL URL Disclosure - source
  • SSL.com: Invalid combinations of countryName, stateOrProvinceName, and localityName attributes - source
  • SECOM: Missing Prior Notification and Approval for a Cross-Certificate Extending Trust to Externally-Operated JPRS CAs - source
  • SECOM: Inaccurate CP/CPS description regarding the basicConstraints extension of OCSP responder certificates by Cybertrust Japan (CTJ) - source
  • Asseco DS / Certum: Incorrect Country in certificate - source
  • Exploring the interaction between descriptive and normative language in CP/CPS documents and the potential for confusion - source
  • Firmaprofesional: Delayed publication of 2026 Audit Attestation Letters - source
  • eMudhra emSign PKI Services: Test Website TLS Certificates Issued Against CP/CPS. - source
  • GlobalSign: StateOrProvince and LocalityName value inconsistency - source
  • Let's Encrypt: CPS missing root program attestation - source
  • Actalis: failure to timely update CP/CPS for AgID SubCAs - source
  • Actalis: Issuance of Server TLS Certificates with id-kp-clientAuth against CPS - source
  • Actalis: Undisclosed Subordinate CA Certificate - source
  • SwissSign: Invalid Entry in State field - source
  • ACCV: Issuance of Server TLS Certificates with CP/CPS Discrepancies - source
  • Sectigo: jurisdictionCountry versus organizationIdentifier mismatch in QWAC - source
  • D-TRUST: Incomplete Disclosure of CRL URLs - source
  • HARICA: Issuance of Server TLS Certificates with id-kp-clientAuth KeyPurposeID against CP/CPS - source
  • NETLOCK: OCSP Service Returning Error for Issued Certificate - source
  • NETLOCK: Failure to file a preliminary incident report within 72 hours (OCSP responder incident, Bug 2051459) - source
  • Google Trust Services: CPS Missing root program attestation - source
  • Actalis: Incorrect CRL Distribution Point in TLS Server Certificates - source
  • DigiCert: jurisdictionCountry in EV certificate - source
  • SDAIA: Missing S/MIME WebTrust audit coverage - source

Check your certificate now

See whether any of this week's CA incidents affect a certificate you're running - free, no account required.

Scan my domain

Resolved this week

  • Certainly: Missing audit log entries for certificates issued during capacity testing - source
  • D-Trust: CRL URL Disclosure - source
  • Sectigo: Incorrect jurisdictionStateOrProvinceName attribute value in Code Signing certificate - source
  • GlobalSign: SubCA created with incorrect CPS Policy OID - source
  • Firmaprofesional: Chrome Root Program Policy - Incorrect CCADB hierarchy associations - source
  • SwissSign: Potential error in stateOrProvinceName - source
  • HARICA: TLS server certificate issuance against CP/CPS - source
  • HARICA: Issuance of Server TLS Certificates without AIA OCSP URI against CP/CPS - source

Get this digest in your inbox

Subscribe to receive this digest by email.