← AC Camerfirma, S.A. cases
Bugzilla #1390977 Certificate Problem Report

Camerfirma: Non-BR-Compliant Certificate Issuance

RESOLVED FIXED AC Camerfirma, S.A.
AI Summary

Camerfirma faced issues with the issuance of certificates that contained invalid DNS names, including internal server names and URLs. The CA acknowledged the problems after they were reported in the Mozilla security policy forum and confirmed that they had ceased issuing such certificates. They provided a list of affected certificates and outlined steps taken to rectify the situation, including revocation of problematic certificates and implementation of new technical controls to prevent future occurrences. Despite these measures, concerns were raised about the adequacy of their responses and the systemic issues that allowed these problems to arise.

Model: gpt-4o-mini Generated: 2026-06-13 17:03 UTC Confidence: 0.90
Chronology
  1. Initial report of issues with Camerfirma's certificates.
  2. Revocation of the first set of problematic certificates.
  3. Revocation of the second set of problematic certificates.
  4. Implementation of new technical controls in the PKI platform.
  5. Final confirmation of completion of action items.
Participants
Ramiro Muñoz Muñoz Kathleen Wilson Ryan Sleevi Gervase Markham Jonathan Rudenberg
External References
Similar Local Cases
#1391087 RESOLVED Certificate Problem Report Opened 2017-08-16 · Closed 2023-02-22 · 71% similar
Visa: Non-BR-Compliant Certificate Issuance
#1390988 RESOLVED Certificate Problem Report Opened 2017-08-16 · Closed 2023-02-22 · 71% similar
Consorci AOC: Non-BR-Compliant Certificate Issuance
#1350615 RESOLVED Certificate Problem Report Opened 2017-03-25 · Closed 2022-11-14 · 66% similar
Camerfirma: Startcom are issuing by proxy using Camerfirma
#1393557 RESOLVED Certificate Problem Report Opened 2017-08-24 · Closed 2023-02-22 · 65% similar
GlobalSign: Non-BR-Compliant Certificate Issuance -- RSA key smaller than 2048 bits
#1398247 RESOLVED Certificate Problem Report Opened 2017-09-08 · Closed 2023-02-22 · 63% similar
DocuSign/Keynectis: Non-BR-Compliant OCSP Responders
#1330482 RESOLVED Certificate Problem Report Opened 2017-01-12 · Closed 2023-02-22 · 63% similar
GoDaddy: New GoDaddy incorrect issuance bug appears to be regression of 2010 issue
#1368171 RESOLVED Certificate Problem Report Opened 2017-05-26 · Closed 2024-06-30 · 63% similar
Firmaprofesional: Non-audited, non-technically-constrained intermediate certificates
#1509002 RESOLVED Certificate Problem Report Opened 2018-11-21 · Closed 2023-02-22 · 60% similar
Camerfirma: MULTICERT certificates with a validity period greater than 825 days

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action