Camerfirma: Non-BR-Compliant Issuance - DNSName is empty
This case concerns Camerfirma issuing four certificates that were later identified as non-BR-compliant due to an empty DNSName. The CA reported that it received information about four non-revoked certificates via mozilla.dev.security.policy and then revoked them on 2018-03-05 between 8:00 and 10:00 AM (UTC). Camerfirma stated that its earlier manual procedure (in place until 2018-02-14) queried crt.sh for linting results using a rolling minnotbefore parameter, but that these certificates did not appear when expected. After deploying cablint and x509lint technical controls on 2018-02-14, Camerfirma said it analyzes pre-certificates and does not issue a certificate when a FATAL or ERROR message occurs. A Fastly participant asked whether Camerfirma had rescanned its entire certificate database for the error and requested updates once all identified certificates were revoked. Camerfirma later confirmed that all certificates identified as erroneous in its analysis had been revoked, and Fastly marked remediation complete and resolved the bug.
- Four certificates were issued by Camerfirma that were later identified as erroneous/non-BR-compliant (DNSName empty).
- Camerfirma deployed cablint and x509lint technical controls for pre-certificate analysis.
- Camerfirma revoked the four identified non-revoked certificates.
- Camerfirma confirmed the identified erroneous certificates had been revoked; remediation was marked complete.
- AC Camerfirma, S.A. — Juan Angel Martin reported four misissued certificates, described the prior linting query process, stated the certificates were revoked on 2018-03-05, and explained that after 2018-02-14 cablint/x509lint controls prevent issuance on FATAL/ERROR.
- Fastly representative — W. Thayer asked whether Camerfirma rescanned its entire certificate database for the error and what was found.
- AC Camerfirma, S.A. — Juan Angel Martin added automated analysis results for the misissued certificates.
- AC Camerfirma, S.A. — He provided a link to the analysis results on a mozilla.dev.security.policy thread.
- Fastly representative — W. Thayer asked the bug to be updated when all identified certificates had been revoked.
- AC Camerfirma, S.A. — Juan Angel Martin confirmed that all certificates identified as erroneous in the analysis had been revoked.
- Fastly representative — Fastly stated remediation was complete and resolved the bug.