Skip to content

Draft: HARICA's clientAuth Incident Shows What Chrome Actually Wants From CP/CPS Compliance#40

Draft
krakenhavoc wants to merge 1 commit into
mainfrom
blog/draft-harica-clientauth-cps-drift-2026-07-22
Draft

Draft: HARICA's clientAuth Incident Shows What Chrome Actually Wants From CP/CPS Compliance#40
krakenhavoc wants to merge 1 commit into
mainfrom
blog/draft-harica-clientauth-cps-drift-2026-07-22

Conversation

@krakenhavoc

@krakenhavoc krakenhavoc commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

Draft blog post: HARICA continued issuing TLS certificates with the id-kp-clientAuth EKU for about a month past its own CP/CPS cutoff, after failing to track Chrome's extension of the leaf-certificate deadline from June 15, 2026 to March 15, 2027. Chrome's response in the incident bug explicitly rejects training and manual-review remediations, demanding automated per-profile CP/CPS conformance controls instead.

Sources used:

Most recent existing posts checked for uniqueness:

  • public-ca-eku-separation-june-2026.md (2026-05-27) — covers the DigiCert/Sectigo intermediate cutover and Chrome policy deadlines for the same EKU separation, but not this HARICA incident
  • sc098v2-caa-rfc8657-mandatory.md (2026-05-20) — different topic (CAA parameters)
  • lets-encrypt-generation-y-transition.md (2026-05-13) — different topic (Let's Encrypt root transition)

Why this topic, this week: The HARICA incident is actively unfolding (reported ~July 17, revocations began July 20, root cause report due July 24) and gives a distinct governance angle, a CA's own CP/CPS drifting out of sync with a moving root program deadline, that our prior EKU post didn't cover.

HARICA continued issuing TLS certificates with the clientAuth EKU for
about a month past its own CP/CPS cutoff after failing to track Chrome's
policy extension. Post covers the Bugzilla incident timeline, Chrome's
rejection of training/manual-review remediations, an openssl check for
affected certs, and what it means for auditing CA compliance posture.
@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying web with  Cloudflare Pages  Cloudflare Pages

Latest commit: a1115a7
Status: ✅  Deploy successful!
Preview URL: https://cf439d9f.web-f5e.pages.dev
Branch Preview URL: https://blog-draft-harica-clientauth.web-f5e.pages.dev

View logs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant