← Autoridad de Certificacion Firmaprofesional cases
Bugzilla #1455119 Ca Certificate Compliance

Firmaprofesional: Undisclosed Intermediate certificate

RESOLVED FIXED Autoridad de Certificacion Firmaprofesional
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Wayne Thayer reported that Firmaprofesional failed to disclose an intermediate CA certificate as required by section 5.3 of the Mozilla root store policy. The report included a crt.sh disclosure link and requested that Firmaprofesional disclose the certificate and provide an incident report as described in Mozilla’s misissuance incident reporting guidance. Firmaprofesional’s representative (chemalogo) responded that the certificate was considered “technically constrained” and therefore did not need to be added to the CA Community in Salesforce, attaching a CCADB warning screenshot. Wayne Thayer disputed that characterization by referencing section 5.3.1 and the certificate’s serial number, and stated that the certificate did not meet the definition of “technically constrained,” while noting it could bypass the warning and be added. Firmaprofesional later created incident reports for the identified certificates and linked them to separate Bugzilla issues (1464335 and 1464359). The bug was resolved as FIXED, and a later comment stated that incident reports were filed and resolved in separate bugs for both certificates identified in the thread.

Model: gpt-5.4-nano Generated: 2026-06-13 17:47 UTC Revised: 2026-06-16 18:05 UTC Confidence: 0.86 9 comments
Chronology
  1. Wayne Thayer reported Firmaprofesional’s intermediate CA certificate was not disclosed as required by Mozilla root store policy.
  2. Firmaprofesional responded that the certificate was treated as technically constrained and attempted CCADB submission.
  3. Firmaprofesional created incident reports for the identified certificates and linked them to separate Bugzilla issues.
  4. A follow-up comment confirmed incident reports were filed and resolved in separate bugs for both certificates.
Thread Activity
  1. Fastly representative — Reported that Firmaprofesional failed to disclose an intermediate CA certificate per Mozilla root store policy section 5.3 and requested disclosure plus an incident report with links to Mozilla guidance.
  2. Isigma representative — Responded that Firmaprofesional believed the certificate was technically constrained and attached a CCADB warning screenshot.
  3. Fastly representative — Asked Firmaprofesional to confirm the certificate serial number and argued it did not meet the definition of technically constrained under section 5.3.1.
  4. Isigma representative — Confirmed the issue was addressed and stated it was already done after bypassing the warning.
  5. Fastly representative — Raised an additional policy concern that no audit information was provided in the CCADB record and requested incident reports for both issues.
  6. Isigma representative — Created an incident report for one of the certificates and linked it to bug 1464335.
  7. Isigma representative — Created an incident report for the second certificate and linked it to bug 1464359.
  8. Fastly representative — Confirmed incident reports were filed and resolved in separate bugs for both CA certificates identified.
Participants
Fastly representative Isigma representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1497700 RESOLVED Ca Certificate Compliance Opened 2018-10-09 · Closed 2022-11-14 · 70% similar
DocuSign/Keynectis: Undisclosed Intermediate certificate
#1464335 RESOLVED Ca Certificate Compliance Opened 2018-05-25 · Closed 2023-02-22 · 70% similar
Firmaprofesional: Undisclosed Intermediate certificate SIGNE
#1368171 RESOLVED Ca Certificate Compliance Incident Opened 2017-05-26 · Closed 2024-06-30 · 68% similar
Firmaprofesional: Non-audited, non-technically-constrained intermediate certificates
#1538638 RESOLVED Ca Certificate Compliance Self Reported Incident Revocation Issue Opened 2019-03-25 · Closed 2023-02-22 · 68% similar
Firmaprofesional: AC Firmaprofesional - INFRAESTRUCTURA insufficient serial number entropy
#1700145 RESOLVED Ca Certificate Compliance Opened 2021-03-22 · Closed 2023-02-22 · 67% similar
Firmaprofesional: incorrect reserved CA/B Forum OIDs in certificates
#1649943 RESOLVED Ca Certificate Compliance Opened 2020-07-02 · Closed 2023-02-22 · 66% similar
Firmaprofesional: Incorrect OCSP Delegated Responder Certificate
#1398240 RESOLVED Ca Certificate Compliance Incident Opened 2017-09-08 · Closed 2023-02-22 · 64% similar
Firmaprofesional: Non-BR-Compliant OCSP Responders
#1367842 RESOLVED Ca Certificate Compliance Incident Opened 2017-05-25 · Closed 2023-02-22 · 61% similar
TurkTrust: Non-audited, non-technically-constrained intermediate certs

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action