Camerfirma: Intermediate certificates issued with the same issuer and serial number
This case concerns AC Camerfirma, S.A. issuing intermediate certificates with the same issuer and serial number, which the reporter described as a violation of the certificate serial number uniqueness requirement in the BRs and RFC5280 4.1.2.2. The reporter asked Camerfirma to provide an incident report in the bug. Camerfirma provided an incident report stating it became aware of the problem after issuing a SubCA in February 2010, and that the SubCA (used for only six test certificates) was not used anymore since 08-11-2014. Camerfirma stated it used a wrong template during the SubCA certificate creation process and that templates are now approved by technical management and reviewed by its internal auditor before going into production. Mozilla asked follow-up questions about why hard-coded serial numbers/templates existed and whether the practices were before they were forbidden. Camerfirma responded with explanations about the manual ceremony process, the timing of BR requirements, and that the certificates were issued before the existence of the BRs. The bug was closed as FIXED, with Mozilla indicating that given the age of the problem and the steps taken, they could close it.
- Camerfirma issued a SubCA used for test certificates, later identified as producing certificates with the same issuer and serial number.
- Camerfirma stopped using the SubCA that had been used for test certificates.
- Mozilla CA Program case opened regarding Camerfirma certificates with duplicate issuer/serial numbers.
- Mozilla representative — Reported that Camerfirma issued intermediate certificates with the same issuer and serial number and requested an incident report.
- Mozilla representative — Provided an incident report text including affected certificates, a timeline of awareness/actions, and process explanations (wrong template, manual generation in an offline environment).
- Mozilla representative — Asked whether the right assignee was set and requested more incident-report detail, including questions about hard-coded serial numbers and BR compliance concerns.
- AC Camerfirma, S.A. — Answered questions about why hard-coded serial numbers/templates existed, why entropy requirements did not apply at the time, and confirmed the certificates were issued before the practices were forbidden.
- Mozilla representative — Indicated that, given the age of the problem and process improvements, Mozilla could close the case.