← AC Camerfirma, S.A. cases
Bugzilla #1455147 Ca Documents Repository Issue

Camerfirma: Missing audit/disclosure for intermediate certificates

RESOLVED FIXED AC Camerfirma, S.A.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Wayne Thayer (Fastly) reported that Camerfirma had not disclosed required audit information in the Common CA Database (CCADB) for an intermediate certificate that chains up to a Mozilla-program root and is capable of issuing S/MIME certificates but is not name constrained, as required by Mozilla root store policy section 5.3. The report also noted that two additional intermediate certificates with CN="MULTICERT SSL Certification Authority 001" were issued and were not disclosed within 7 days, and that one of them had been revoked but still needed disclosure. Camerfirma provided updated information and an audit certificate, and later posted an incident report describing how the CA became aware of the problem, a timeline of actions, and why disclosure was missed (including a procedure gap and unavailability of the responsible person and backup). Camerfirma stated it had disclosed the certificates on July 31 and described remediation steps, including adding a third point of contact for CCADB disclosure and modifying its procedure. The incident report and follow-up discussion addressed the disclosure failures; the bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 17:47 UTC Revised: 2026-06-16 18:05 UTC Confidence: 0.84 9 comments
Chronology
  1. Mozilla CA Program issue raised regarding missing CCADB audit disclosure for a Camerfirma intermediate certificate.
  2. A relevant Camerfirma intermediate certificate was issued.
  3. A second relevant Camerfirma intermediate certificate was issued (and later revoked).
  4. Camerfirma disclosed the missed intermediate certificates in CCADB.
  5. Camerfirma posted an incident report and described remediation steps.
  6. Mozilla reviewer responded that the proposed procedural change did not address the policy requirement timing.
Thread Activity
  1. Fastly representative — Wayne Thayer cited the April 2018 Mozilla CA Communication and asked Camerfirma to add required audit information to CCADB or revoke the intermediate certificate, and to provide an incident report.
  2. AC Camerfirma, S.A. — Juan Angel Martin said he updated the required information.
  3. Fastly representative — Wayne Thayer requested the audit report (not just the audit certificate) containing the information listed in Mozilla root store policy section 3.1.4.
  4. Fastly representative — Wayne Thayer stated that two new intermediate certificates were issued but not disclosed within 7 days, and requested CCADB disclosure plus an incident report explaining why disclosure was missed.
  5. Fastly representative — Wayne Thayer referenced Camerfirma’s incident report posted in response to the request and summarized its contents (timeline, cause, and remediation steps).
  6. AC Camerfirma, S.A. — Juan Angel Martin reiterated remediation steps (adding a third CCADB point of contact) and said Camerfirma modified its procedure to not deliver the intermediate certificate until it is disclosed in CCADB.
  7. Fastly representative — Wayne Thayer replied that the proposed procedural change did not help because the policy requires disclosure within a week of creation.
Participants
Fastly representative AC Camerfirma, S.A.
Similar Local Cases
#1549861 RESOLVED Repository Issue Self Reported Incident Opened 2019-05-07 · Closed 2023-02-22 · 80% similar
Camerfirma: Outdated audit statements for intermediate certs
#1605126 RESOLVED Ca Documents Opened 2019-12-19 · Closed 2024-06-30 · 70% similar
PKIoverheid: Missing intermediate CA certificates in WTBR audit statements Staat der Nederlanden 2017/2018
#1596949 RESOLVED Ca Documents Policy Document Issue Self Reported Incident Opened 2019-11-15 · Closed 2023-02-22 · 70% similar
FNMT: CP/CPS lack CAA processing details
#1688382 RESOLVED Ca Documents Incident Policy Document Issue Opened 2021-01-23 · Closed 2023-02-22 · 69% similar
Camerfirma: No disclosure of verification sources
#2023563 RESOLVED Ca Documents Repository Issue Opened 2026-03-16 · Closed 2026-05-07 · 69% similar
SECOM: Incorrect CCADB Non-Audit Document References for FUJIFILM Fnet CA - C
#1572234 RESOLVED Self Reported Incident Repository Issue Opened 2019-08-07 · Closed 2023-02-22 · 69% similar
GoDaddy: cross certificate disclosure to CCADB
#1417771 RESOLVED Ca Documents Incident Opened 2017-11-16 · Closed 2024-06-30 · 69% similar
DigiCert: Symantec non-constrained/non-disclosed intermediate CA certificates
#1565494 RESOLVED Audit Finding Self Reported Incident Repository Issue Opened 2019-07-12 · Closed 2024-06-30 · 69% similar
CFCA: Missed annual CPS update publication on website in 2018

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action