CA/PKI Weekly Digest - Aug 31 - Sep 7, 2026
Stay alert of the changes for your SSL/TLS cert
TLS Radar continuously monitors every certificate across your domains and alerts you weeks before anything expires, and also catches the silent failure modes - chain breaks, weak ciphers, hostname mismatches, risky EKUs, and distrust events - that keep a site from opening in every browser. Built for solo developers monitoring a handful of sites and for enterprise teams managing thousands of certificates across multiple environments.
A weekly summary of certificate authority incidents and compliance activity, sourced from Mozilla's public CA Program tracker.
New this week
- Sectigo: No revocation after CP/CPS language involving extendedKeyUsage found to be subject to multiple interpretations - source
- TWCA: CPR subject.countryName - source
- DigiCert: CPR subject.countryName - source
- SECOM: Five Subordinate CA Certificates Issued Without Apple Prior Approval for Cybertrust Japan (CTJ) - source
- Sectigo: CP/CPS language involving extendedKeyUsage found to be subject to multiple interpretations - source
- Firmaprofesional: CP/CPS missing Chrome Root Program and CCADB policy attestation - source
- Chunghwa Telcom: Delay of 2025 WebTrust for CA Audit Reports seals for ePKI & HiPKI - source
Updates on open incidents
- Let's Encrypt: CRLs Temporarily Missing Revoked Serials - source
- IdenTrust: Expired certificates for "Revoked" test websites - source
- SwissSign: Delayed revocation in Bug 2057448 - source
- ACCV: Delayed revocation related to Bugzilla #2061746 - source
- SDAIA: Delayed Revocation related to Bugzilla #2056942 - source
- CFCA: Cross-signed certificate missing the Extended Key Usage (EKU) extension - source
- GlobalSign: Unicode replacement character issue in Subject - source
- eMudhra emSign PKI Services: www Subdomain Inclusion in Certificate SAN via ACME Issuance Workflow - source
- Asseco DS / Certum: Incomplete CRL Disclosure in CCADB - source
- eMudhra emSign PKI Services: Invalid Subject Locality/State Values - source
- Firmaprofesional: Chrome Root Progam Policy - Dedicated TLS hierarchy / EKU requirements - source
- Asseco DS / Certum: Delayed publication of Full Incident Report for Bug 2055775 - source
- NETLOCK: Failure to Respond to a Certificate Problem Report Within 24 Hours - source
- SHECA: Disclosure alerts indicating audit information missing for 2 Sub-CAs - source
- SHECA: Failed to provide a preliminary incident report within 72 hours - source
- iTrusChina: Inconsistent EKUs in CP/CPS and Mis-issuance of TLS Certificates with clientAuth against CP/CPS - source
- CFCA: Incorrect countryName values in OV subscriber certificates - source
- CFCA: Delayed response to CPR related with bug 2058918 - source
- Amazon Trust Services: CP/CPS missing explicit adherence to latest version of policies - source
- Certainly: Test Website Certificate Renewal Failure Following Production Deployment Drift - source
- Disig: CP/CPS misstatement regarding Key Usage criticality for TLS certificates - source
- Microsoft PKI Services: Missed Seven-Day Update for Bugzilla 2059818 - source
- GoDaddy: CCADB Missing Partitioned CRL URL Disclosure - source
- SSL.com: Invalid combinations of countryName, stateOrProvinceName, and localityName attributes - source
- SECOM: Missing Prior Notification and Approval for a Cross-Certificate Extending Trust to Externally-Operated JPRS CAs - source
- SECOM: Inaccurate CP/CPS description regarding the basicConstraints extension of OCSP responder certificates by Cybertrust Japan (CTJ) - source
- Asseco DS / Certum: Incorrect Country in certificate - source
- Exploring the interaction between descriptive and normative language in CP/CPS documents and the potential for confusion - source
- Firmaprofesional: Delayed publication of 2026 Audit Attestation Letters - source
- eMudhra emSign PKI Services: Test Website TLS Certificates Issued Against CP/CPS. - source
- GlobalSign: StateOrProvince and LocalityName value inconsistency - source
- Let's Encrypt: CPS missing root program attestation - source
- Actalis: failure to timely update CP/CPS for AgID SubCAs - source
- Actalis: Issuance of Server TLS Certificates with id-kp-clientAuth against CPS - source
- Actalis: Undisclosed Subordinate CA Certificate - source
- SwissSign: Invalid Entry in State field - source
- ACCV: Issuance of Server TLS Certificates with CP/CPS Discrepancies - source
- Sectigo: jurisdictionCountry versus organizationIdentifier mismatch in QWAC - source
- D-TRUST: Incomplete Disclosure of CRL URLs - source
- HARICA: Issuance of Server TLS Certificates with id-kp-clientAuth KeyPurposeID against CP/CPS - source
- NETLOCK: OCSP Service Returning Error for Issued Certificate - source
- NETLOCK: Failure to file a preliminary incident report within 72 hours (OCSP responder incident, Bug 2051459) - source
- Google Trust Services: CPS Missing root program attestation - source
- Actalis: Incorrect CRL Distribution Point in TLS Server Certificates - source
- DigiCert: jurisdictionCountry in EV certificate - source
- SDAIA: Missing S/MIME WebTrust audit coverage - source
Check your certificate now
See whether any of this week's CA incidents affect a certificate you're running - free, no account required.
Scan my domainResolved this week
- Certainly: Missing audit log entries for certificates issued during capacity testing - source
- D-Trust: CRL URL Disclosure - source
- Sectigo: Incorrect jurisdictionStateOrProvinceName attribute value in Code Signing certificate - source
- GlobalSign: SubCA created with incorrect CPS Policy OID - source
- Firmaprofesional: Chrome Root Program Policy - Incorrect CCADB hierarchy associations - source
- SwissSign: Potential error in stateOrProvinceName - source
- HARICA: TLS server certificate issuance against CP/CPS - source
- HARICA: Issuance of Server TLS Certificates without AIA OCSP URI against CP/CPS - source
Get this digest in your inbox
Subscribe to receive this digest by email.