Firmaprofesional: Undisclosed Intermediate certificate
Wayne Thayer reported that Firmaprofesional failed to disclose an intermediate CA certificate as required by section 5.3 of the Mozilla root store policy. The report included a crt.sh disclosure link and requested that Firmaprofesional disclose the certificate and provide an incident report as described in Mozilla’s misissuance incident reporting guidance. Firmaprofesional’s representative (chemalogo) responded that the certificate was considered “technically constrained” and therefore did not need to be added to the CA Community in Salesforce, attaching a CCADB warning screenshot. Wayne Thayer disputed that characterization by referencing section 5.3.1 and the certificate’s serial number, and stated that the certificate did not meet the definition of “technically constrained,” while noting it could bypass the warning and be added. Firmaprofesional later created incident reports for the identified certificates and linked them to separate Bugzilla issues (1464335 and 1464359). The bug was resolved as FIXED, and a later comment stated that incident reports were filed and resolved in separate bugs for both certificates identified in the thread.
- Wayne Thayer reported Firmaprofesional’s intermediate CA certificate was not disclosed as required by Mozilla root store policy.
- Firmaprofesional responded that the certificate was treated as technically constrained and attempted CCADB submission.
- Firmaprofesional created incident reports for the identified certificates and linked them to separate Bugzilla issues.
- A follow-up comment confirmed incident reports were filed and resolved in separate bugs for both certificates.
- Fastly representative — Reported that Firmaprofesional failed to disclose an intermediate CA certificate per Mozilla root store policy section 5.3 and requested disclosure plus an incident report with links to Mozilla guidance.
- Isigma representative — Responded that Firmaprofesional believed the certificate was technically constrained and attached a CCADB warning screenshot.
- Fastly representative — Asked Firmaprofesional to confirm the certificate serial number and argued it did not meet the definition of technically constrained under section 5.3.1.
- Isigma representative — Confirmed the issue was addressed and stated it was already done after bypassing the warning.
- Fastly representative — Raised an additional policy concern that no audit information was provided in the CCADB record and requested incident reports for both issues.
- Isigma representative — Created an incident report for one of the certificates and linked it to bug 1464335.
- Isigma representative — Created an incident report for the second certificate and linked it to bug 1464359.
- Fastly representative — Confirmed incident reports were filed and resolved in separate bugs for both CA certificates identified.