Consorci AOC: Non-BR-compliant certificate issuance and related remediation
This case concerns non-BR-compliant TLS certificate issuance by Consorci AOC, including certificates with invalid dNSNames such as internal names and other malformed names. Mozilla opened the bug after problems were reported in mozilla.dev.security.policy, and the opening comment also noted a failure to respond within 24 hours to a problem report submitted through the CA’s published reporting channel. Consorci AOC said it became aware of the issue via this Bugzilla bug, confirmed it had added automated checks, and provided lists of affected certificates. The CA explained that one root cause was incorrect use of a domain parser that omitted suffix validation, and later said its initial historical scan had been incomplete because it focused on internal-name cases and missed other malformed names. During the thread, the CA reported revocation progress, said the last initially identified misissued certificate was revoked on 2017-09-28, and later disclosed additional previously issued misissued certificates that were then revoked. The discussion also covered improvements to pre-issuance validation, use of certlint, preferred name syntax validation, public suffix list checks, and changes to the CA’s problem-reporting process. Later comments discussed another set of non-BR-conforming certificates issued under a Spanish public-administration profile, and the CA said migration to BR-conforming profiles completed on 2018-05-09 and that those previously issued certificates were revoked and replaced. The bug was ultimately resolved FIXED, with a final comment stating remediation was completed.
- A problem report was submitted to the CA's published problem-reporting channel and assigned ticket number 180314.
- The CA said it added additional automatic checks to issuance procedures and began identifying affected certificates.
- The CA said it added suffix validation to production at 14:42 and updated regression tests with invalid public suffixes.
- The CA reported that the last of the initially identified misissued certificates had been revoked.
- The CA disclosed additional previously issued misissued certificates and said their revocation had already been handled.
- The CA said EJBCA certlint-based pre-issuance controls were finally put into place.
- The CA said migration to new BR-conforming certificate profiles was completed.
- The CA said all certificates issued according to the non-BR-conforming "sede electronica" profile had been revoked and replaced.
- Mozilla representative — Mozilla opened the bug, listed reported certificate problems, requested incident details and remediation, and noted a reported failure to respond within 24 hours to a problem report.
- Consorci Administració Oberta de Catalunya (Consorci AOC, CATCert) — The CA attached a certificate list summary.
- Consorci Administració Oberta de Catalunya (Consorci AOC, CATCert) — The CA said it learned of the issue via the bug, confirmed the problem was solved, described affected certificates, and outlined revocation and training steps.
- Titanous representative — Jonathan requested an explanation for why the submitted problem report did not reach the right place and asked that affected certificates be logged to CT.
- Mozilla representative — Gerv marked an earlier CA comment obsolete because comment deletion was not enabled.
- Community commenter — Ryan asked for more detail on systemic causes, technical controls, and remediation, and urged stronger technical validation.
- Community commenter — Ryan followed up asking whether the CA could answer the outstanding questions.
- Autoridad de Certificacion Firmaprofesional — A participant said the comments were being reviewed to improve and automate the issuance pipeline.
- Community commenter — Ryan asked whether there were any updates.
- Consorci Administració Oberta de Catalunya (Consorci AOC, CATCert) — The CA described its domain-validation flow, said the incident was caused by bad parser usage and missing suffix validation, and said non-ASCII DNS names were not allowed.
- Community commenter — Ryan suggested additional domain well-formedness checks and summarized his understanding of the root cause and remediation timeline.
- Consorci Administració Oberta de Catalunya (Consorci AOC, CATCert) — The CA apologized for missing the original problem report, explained support-process failures, proposed a dedicated multilingual SSL problem-reporting form, and said revocation was being accelerated.
- Consorci Administració Oberta de Catalunya (Consorci AOC, CATCert) — The CA said only one unrevoked misissued certificate remained and described further planned validation changes.
- Consorci Administració Oberta de Catalunya (Consorci AOC, CATCert) — The CA announced that the last misissued certificate had been revoked.
- Community commenter — Ryan clarified that additional checks were still needed because forbidding non-ASCII characters and the root label alone would not catch all invalid domains.
- Mozilla representative — Gerv asked whether the CA had updated its remediation plans to address Ryan's concerns.
- Consorci Administració Oberta de Catalunya (Consorci AOC, CATCert) — The CA said it had implemented preferred name syntax validation, daily public suffix list updates, post-issuance checks against issued certificates, and manual WHOIS review after validation.
- Fastly representative — Wayne relayed a report of another certificate with an invalid SAN entry and quoted the CA saying it would investigate whether more cases existed.
- Consorci Administració Oberta de Catalunya (Consorci AOC, CATCert) — The CA attached an updated certificate list summary.
- Consorci Administració Oberta de Catalunya (Consorci AOC, CATCert) — The CA said it found another misissued certificate with CN "http://www.concactiva.cat", said revocation was already handled, and said the newly identified certificates predated the new controls.
- Mozilla representative — Gerv questioned whether validation was happening post-issuance and asked why certlint had not detected the newly disclosed certificates earlier.
- Consorci Administració Oberta de Catalunya (Consorci AOC, CATCert) — The CA said pre-issuance validations had been in place since August 2017, but its initial historical search had only looked for local-name issues and missed other malformed CNs.
- Mozilla representative — Gerv asked what procedure had been used for the initial detection and whether certlint had been run across the entire certificate database.
- Consorci Administració Oberta de Catalunya (Consorci AOC, CATCert) — The CA attached another updated certificate list summary.
- Consorci Administració Oberta de Catalunya (Consorci AOC, CATCert) — The CA said the initial detection had only looked for certain categories, disclosed six more certificates with invalid CN characters, and proposed additional corrective measures including centralizing issuance and implementing EJBCA 6.11 pre-issuance controls.
- Fastly representative — Wayne asked how a certificate issued in January 2018 could exist if pre-issuance validations including certlint had been in place since August 2017.
- Consorci Administració Oberta de Catalunya (Consorci AOC, CATCert) — The CA corrected earlier statements, said EJBCA certlint-based pre-issuance controls were finally implemented on 2018-03-14, and said weekly post-issuance manual crt.sh reviews had been used since comment 25.
- Fastly representative — Wayne said crt.sh showed continued misissuance through 2018-03-12 and asked how the CA would remediate all additional misissued certificates.
- Consorci Administració Oberta de Catalunya (Consorci AOC, CATCert) — The CA said certificates flagged after 2018-03-12 were public-administration SSL certificates affected by a profile issue discussed in another bug and said deployment of new eIDAS-compliant profiles was scheduled for 2018-05-09.
- Fastly representative — Wayne asked why it had taken so long to resolve the profile problem.
- Consorci Administració Oberta de Catalunya (Consorci AOC, CATCert) — The CA said it had waited for Spanish supervisory-body authorization and planned to enter production with fully eIDAS- and CA/B Forum-compliant profiles on 2018-05-09.
- Community commenter — Ryan challenged the claim that supervisory-body approval was required before changing profiles and said the certificates were misissued once the old legal basis had been repealed.
- Consorci Administració Oberta de Catalunya (Consorci AOC, CATCert) — The CA provided legal-context references, explained its interpretation of eIDAS and Spanish interoperability requirements, and said it was open to progressive revocation and reissuance from 2018-05-09.
- Community commenter — Ryan said the cited material still did not show the CA was required to continue issuing the non-compliant profile after repeal of the old law.
- Consorci Administració Oberta de Catalunya (Consorci AOC, CATCert) — The CA provided further references about Spanish certificate profiles, eIDAS qualification, and national validation-system interoperability.
- Fastly representative — Wayne asked whether the CA could have revised its profiles to become BR compliant between repeal of the Spanish law and July 1, 2017, and said revocation of previous certificates would be advisable.
- Fastly representative — Wayne requested an update on whether the profile change had gone live and whether all misissued certificates were being revoked.
- Consorci Administració Oberta de Catalunya (Consorci AOC, CATCert) — The CA said migration to BR-conforming profiles completed on 2018-05-09, provided example certificates, and said revocation and reissuance of previously issued "sede electronica" certificates had started and were planned to finish by the end of June.
- Fastly representative — Wayne replied to the CA's question about using crt.sh to identify non-revoked certificates.
- Consorci Administració Oberta de Catalunya (Consorci AOC, CATCert) — The CA said all certificates issued under the non-BR-conforming "sede electronica" profile had been revoked and replaced.
- Fastly representative — Wayne stated that remediation was completed.