← AC Camerfirma, S.A. cases
Bugzilla #1420871 Certificate Misissuance

Camerfirma: Potential mis-issuance based on CAA records (CAA checking bypassed)

RESOLVED FIXED AC Camerfirma, S.A.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The case concerns a potential mis-issuance by Camerfirma where CAA records indicated that issuance was not permitted. Quirin Scheitle opened the bug after observing that Camerfirma appeared not to have checked CAA records for the affected certificate, and asked whether CAA checking was bypassed and what response (if any) was received. Camerfirma’s representative stated that Camerfirma bypassed CAA checking for the issuance based on a sentence in the BR that they interpreted as making CAA checking optional when a CT pre-certificate was created and logged, and they acknowledged this was a misunderstanding. Camerfirma reported that the affected certificate was already revoked on 28/Nov/2017 and that it no longer appeared on misissued.com/batch/32. They also stated that CAA check control had been activated in all their RAs. Gerv asked for clarification and a timeline, and Camerfirma further explained that they thought CT already performed the CAA checking. The bug was closed out by Wendy Thayer as the certificate had been revoked and no further actions were pending.

Model: gpt-5.4-nano Generated: 2026-06-13 17:40 UTC Revised: 2026-06-16 18:04 UTC Confidence: 0.62 9 comments
Chronology
  1. An AC Camerfirma-issued certificate was logged with issuance times that corresponded to CAA records for am-hosting.de.
  2. The affected certificate was revoked by Camerfirma.
  3. The bug was closed out as the certificate was revoked and no further actions were pending.
Thread Activity
  1. Scheitle representative — Filed the bug, stating Camerfirma appeared not to have checked CAA records and asking whether CAA checking was bypassed and what response was received.
  2. AC Camerfirma, S.A. — Explained that Camerfirma bypassed CAA checking due to a misunderstanding of BR wording, and stated the affected certificate was revoked on 28/Nov/2017 and that CAA check control was activated in all RAs.
  3. Mozilla representative — Requested clarification on what Camerfirma actually did regarding CAA checking and asked for a timeline of events.
  4. Scheitle representative — Noted that Camerfirma’s interpretation could be read as CT logging removing the need for CAA checking, pointing to the BR sentence wording.
  5. Mozilla representative — Pressed for clarification on how Camerfirma interpreted the last clause of the BR sentence about CAA being checked.
  6. AC Camerfirma, S.A. — Acknowledged confusion around the word “optional,” and stated they believed CT already performed the checking, apologizing for the misunderstanding.
  7. Fastly representative — Closed the case, stating the certificate had been revoked and no further actions were pending.
Participants
Scheitle representative Mozilla representative AC Camerfirma, S.A. Fastly representative
Similar Local Cases
#1398269 RESOLVED Certificate Misissuance Opened 2017-09-08 · Closed 2023-02-22 · 72% similar
DigiCert: Non-BR-Compliant OCSP Responders
#1390977 RESOLVED Certificate Misissuance Opened 2017-08-16 · Closed 2023-02-22 · 72% similar
Camerfirma: Non-BR-Compliant Certificate Issuance
#1579299 RESOLVED Repository Issue Certificate Misissuance Opened 2019-09-06 · Closed 2023-02-22 · 67% similar
Asseco DS / Certum: non-audited intermediate certificate
#1398428 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-09-09 · Closed 2023-02-22 · 67% similar
Amazon Trust Services: CAA Misissuances
#1521623 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-01-21 · Closed 2024-05-09 · 67% similar
Amazon Trust Services: Failure to comply with RFC 5280
#1015767 RESOLVED Certificate Misissuance Opened 2014-05-25 · Closed 2022-11-14 · 66% similar
startcom: still issuing < 2048 bit certificates
#1625421 RESOLVED Certificate Misissuance Opened 2020-03-27 · Closed 2024-05-09 · 66% similar
FNMT: QC Statement that contains at least one of the ETSI ESI statements
#1315018 RESOLVED Certificate Misissuance Opened 2016-11-03 · Closed 2022-11-14 · 66% similar
SHA-1 issuance by GlobalSign root

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action