Camerfirma non-BR-compliant certificate issuance and remediation of invalid DNS names
This case concerns AC Camerfirma’s issuance of TLS/SSL certificates with non-BR-compliant DNS names, including URLs in dNSName SANs and internal server names. The issue was raised in Mozilla’s CA Program after reports in mozilla.dev.security.policy and direct email reports, and Mozilla asked Camerfirma to identify affected certificates, explain how the problem was discovered, and describe remediation and prevention steps. Camerfirma said it stopped issuing the problematic certificates, worked with customers to replace them, and revoked the affected certificates over time. The CA also described adding manual second review, technical DNSName controls in its PKI platform, and linting checks, and later said all reported certificates were revoked and the action items were completed. The bug was ultimately resolved FIXED.
- A certificate later identified as containing internal server names was issued.
- BR revocation deadline for certain internal-name certificates had passed without those certificates being revoked.
- Mozilla opened the bug after reports of non-BR-compliant certificate issuance.
- Camerfirma revoked one of the affected certificates.
- Camerfirma revoked the remaining affected certificate referenced in the thread.
- Camerfirma said its DNSName technical control was implemented.
- Mozilla marked the bug resolved after the reported action items were completed.
- Mozilla representative — Kathleen Wilson opened the bug and requested details on discovery, stopping issuance, affected certificates, root cause, remediation, and future prevention.
- AC Camerfirma, S.A. — Ramiro Muñoz Muñoz said Camerfirma learned of the issue via the problem reporting address, had stopped issuing affected certificates, and was coordinating replacements with customers.
- Community commenter — Ryan Sleevi asked for more detail on systemic causes, controls, and why the CA had not yet provided a fuller analysis.
- Community commenter — Alex Gaynor said he had emailed Camerfirma on July 30 listing three non-compliant certificates and had not received a response.
- AC Camerfirma, S.A. — Ramiro said all reported certificates were revoked except one, and described planned controls including daily review and certlint/x509lint checks.
- AC Camerfirma, S.A. — Ramiro said one certificate remained to be revoked on September 11 and that Camerfirma had deployed a DNSName technical control.
- AC Camerfirma, S.A. — Ramiro said Camerfirma had analyzed the root cause, revoked the internal-name certificates, and activated a control to avoid bad DNSName spellings.
- AC Camerfirma, S.A. — Ramiro provided a fuller root-cause explanation, said all affected certificates were revoked, and described added staffing and process controls.
- AC Camerfirma, S.A. — Ramiro reported the status of the action items, including implemented technical controls and updated procedures.
- Fastly representative — Wayne Thayer said the action items appeared complete and marked the bug resolved.