Firmaprofesional: Undisclosed intermediate certificate SIGNE
Firmaprofesional reported that after issuing a technically constrained sha256withRSA SIGNE subordinate CA (an intermediate certificate), it did not disclose the certificate into the CCADB as required. The CA stated it became aware of the issue through a Mozilla Bugzilla process and referenced a related Bugzilla bug (1455119). In response, Firmaprofesional said it disclosed the affected certificate and updated its internal hierarchy procedures to add CCADB disclosure as a step when issuing new CA certificates. The thread also notes that CCADB was being updated to properly detect intermediate certificates requiring disclosure based on current disclosure requirements for email certificates. A component suggestion was raised by another participant, but the CA’s described remediation focused on disclosure and procedure updates. The bug is marked RESOLVED with resolution FIXED.
- Firmaprofesional issued a technically constrained sha256withRSA SIGNE subordinate CA and later identified that it had not been disclosed into CCADB.
- Firmaprofesional opened the CA Program bug reporting the undisclosed intermediate certificate and requesting disclosure.
- CCADB updates were noted to improve detection of intermediate certificates requiring disclosure.
- The bug was resolved as FIXED.
- Isigma representative — Reported that after issuing the technically constrained sha256withRSA SIGNE subordinate CA, Firmaprofesional did not disclose it into CCADB and said it should have.
- Isigma representative — Provided details including that internal procedures did not include CCADB disclosure for new CA certificates, and stated the CA disclosed the affected certificate and modified internal hierarchy procedures to add the disclosure step.
- Softvision representative — Suggested changing the component to NSS::CA Certificate Mis-Issuance if that was the correct component.
- Fastly representative — Stated that CCADB was being updated to properly detect intermediate certificates requiring disclosure based on current disclosure requirements for email certificates.