ACCV publicly disclosed subordinate CA certificates
This case is about the Government of Spain, Autoritat de Certificació de la Comunitat Valenciana (ACCV) publicly disclosing subordinate CA certificates. The bug includes attachments describing multiple subordinate CAs (e.g., ACCV-CA1, ACCV-CA2, ACCV-CA3, ACCVCA-110, ACCVCA-120, and ACCVCA-130), including whether each issues SSL/EV certificates and providing links to ACCV CPS/CP and Webtrust information. The thread states that ACCVCA-120 was the only issuing SSL CA at the time, and that SSL certificates had been issued with ACCV-CA2 and ACCVCA-120 during ACCV’s operation. Kathleen Wilson closed the bug as resolved, noting that it would continue to be used to provide information about ACCV’s publicly disclosed and audited subordinate CA certificates. The resolution recorded in the bug is “WORKSFORME.”
- ACCV submitted documentation for publicly disclosed subordinate CA certificates (including CPS/CP and Webtrust links) for multiple subordinate CAs.
- Gva representative — Created the bug and attached ACCV-CA1 documentation, stating it does not issue SSL or EV certificates and providing CPS and Webtrust links.
- Gva representative — Attached ACCV-CA2 documentation, stating it issues SSL certificates and providing CPS, CP, and Webtrust links.
- Gva representative — Attached ACCV-CA3 documentation, stating it does not issue SSL or EV certificates and providing CPS and Webtrust links.
- Gva representative — Attached ACCVCA-110 documentation, stating it does not issue SSL or EV certificates and providing CPS and Webtrust links.
- Gva representative — Attached ACCVCA-120 documentation, stating it issues SSL certificates and providing CPS, CP, and Webtrust links.
- Gva representative — Attached ACCVCA-130 documentation, stating it has not yet issued certificates and does not expect to issue EV SSL or certificates, with CPS and Webtrust links.
- Gva representative — Stated that on May 20, 2014, ACCVCA-120 was the only issuing SSL CA and that SSL certificates had been issued with ACCV-CA2 and ACCVCA-120 during ACCV’s operation.
- Mozilla representative — Closed the bug as resolved, stating it would continue to be used to provide information about ACCV’s publicly disclosed and audited subordinate CA certificates.