← AC Camerfirma, S.A. cases
Bugzilla #1405815 Self Reported Incident

Camerfirma: Intermediate certificates issued with the same issuer and serial number

RESOLVED FIXED AC Camerfirma, S.A.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns AC Camerfirma, S.A. issuing intermediate certificates with the same issuer and serial number, which the reporter described as a violation of the certificate serial number uniqueness requirement in the BRs and RFC5280 4.1.2.2. The reporter asked Camerfirma to provide an incident report in the bug. Camerfirma provided an incident report stating it became aware of the problem after issuing a SubCA in February 2010, and that the SubCA (used for only six test certificates) was not used anymore since 08-11-2014. Camerfirma stated it used a wrong template during the SubCA certificate creation process and that templates are now approved by technical management and reviewed by its internal auditor before going into production. Mozilla asked follow-up questions about why hard-coded serial numbers/templates existed and whether the practices were before they were forbidden. Camerfirma responded with explanations about the manual ceremony process, the timing of BR requirements, and that the certificates were issued before the existence of the BRs. The bug was closed as FIXED, with Mozilla indicating that given the age of the problem and the steps taken, they could close it.

Model: gpt-5.4-nano Generated: 2026-06-13 17:11 UTC Revised: 2026-06-16 18:04 UTC Confidence: 0.50 5 comments
Chronology
  1. Camerfirma issued a SubCA used for test certificates, later identified as producing certificates with the same issuer and serial number.
  2. Camerfirma stopped using the SubCA that had been used for test certificates.
  3. Mozilla CA Program case opened regarding Camerfirma certificates with duplicate issuer/serial numbers.
Thread Activity
  1. Mozilla representative — Reported that Camerfirma issued intermediate certificates with the same issuer and serial number and requested an incident report.
  2. Mozilla representative — Provided an incident report text including affected certificates, a timeline of awareness/actions, and process explanations (wrong template, manual generation in an offline environment).
  3. Mozilla representative — Asked whether the right assignee was set and requested more incident-report detail, including questions about hard-coded serial numbers and BR compliance concerns.
  4. AC Camerfirma, S.A. — Answered questions about why hard-coded serial numbers/templates existed, why entropy requirements did not apply at the time, and confirmed the certificates were issued before the practices were forbidden.
  5. Mozilla representative — Indicated that, given the age of the problem and process improvements, Mozilla could close the case.
Participants
Mozilla representative AC Camerfirma, S.A.
Similar Local Cases
#1575530 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-08-21 · Closed 2023-02-22 · 96% similar
Camerfirma: Govern d'Andorra audits
#1672029 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-10-19 · Closed 2023-02-22 · 94% similar
Camerfirma: Failure to abide by Section 8 of Mozilla Policy: Unauthorized, improperly disclosed Subordinate CA
#723722 RESOLVED Self Reported Incident Opened 2012-02-02 · Closed 2022-11-14 · 93% similar
EV SSL certificate (and OCSP response) for www.camerfirma.com fails to meet EV Guidelines
#1586860 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-10-07 · Closed 2023-02-22 · 93% similar
Camerfirma: Invalid authorityKeyIdentifier, violating Mozilla Policy and RFC 5280
#1672409 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2020-10-21 · Closed 2023-02-22 · 88% similar
Camerfirma: suspicious certificate for com.com
#1686524 RESOLVED Self Reported Incident Incident Opened 2021-01-13 · Closed 2023-02-22 · 87% similar
Camerfirma: Certificate issued with 3-year lifespan, unknown policy
#1549861 RESOLVED Repository Issue Self Reported Incident Opened 2019-05-07 · Closed 2023-02-22 · 86% similar
Camerfirma: Outdated audit statements for intermediate certs
#1556806 RESOLVED Certificate Misissuance Self Reported Incident Opened 2019-06-04 · Closed 2023-02-22 · 86% similar
Camerfirma: Infocert misissued certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action