← AC Camerfirma, S.A. cases
Bugzilla #1468000 Policy Document Issue

Camerfirma: Invalid country field in Camerfirma root CA certificates

RESOLVED INVALID AC Camerfirma, S.A.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case reports that four Camerfirma root CA certificates included in Mozilla NSS had an invalid subject country field value. The reporter observed that the certificates used C=EU and stated that “EU is not a country,” and expected the country field to be C=ES. A comment in the thread notes that only country codes listed in ISO 3166 are valid for the “C” field, and another comment cites a Mozilla Baseline Requirements section about the subject:countryName needing the two-letter ISO 3166-1 country code associated with the subject’s location. The bug was later marked RESOLVED with resolution INVALID. In a 2025 comment, the reporter stated that the certificate had been removed from NSS a few years earlier and referenced other Bugzilla IDs as examples. The thread does not describe any CA remediation action in response to the reported field issue.

Model: gpt-5.4-nano Generated: 2026-06-13 17:51 UTC Revised: 2026-06-16 18:06 UTC Confidence: 0.74 9 comments
Chronology
  1. A bug was filed reporting that Camerfirma root CA certificates in Mozilla NSS used C=EU in the subject country field.
  2. Discussion clarified that ISO 3166 country codes are required for the subject “C” field and debated whether EU could be treated as a valid code.
  3. The reporter noted the certificates had been removed from NSS and pointed to related Bugzilla entries.
Thread Activity
  1. Trentalancia representative — Reported that four Camerfirma root CA certificates installed in NSS had an invalid country field (C=EU) and expected C=ES instead.
  2. Trentalancia representative — Cited ISO guidance stating that only ISO 3166-listed country codes are valid for the “C” field.
  3. Fastly representative — Noted the roots had been included in the Mozilla program for more than 7 years, predating documented requirements for these fields.
  4. Sectigo — Argued the report might be wrong, citing ISO 3166 exceptional reservations and discussing how Baseline Requirements define the subject countryName.
  5. Trentalancia representative — Reiterated that the organization is a private Spanish company and requested verification that the country code should be C=ES.
  6. Trentalancia representative — Stated the certificate had been removed from NSS a few years earlier and linked to other Bugzilla IDs.
Participants
Trentalancia representative Mozilla representative Fastly representative Sectigo
Related Bugzilla IDs Mentioned
Similar Local Cases
#1596931 RESOLVED Ca Documents Policy Document Issue Opened 2019-11-15 · Closed 2024-06-30 · 70% similar
DigiCert: Verizon CPS lacks CPR problem reporting instructions
#1688382 RESOLVED Ca Documents Incident Policy Document Issue Opened 2021-01-23 · Closed 2023-02-22 · 68% similar
Camerfirma: No disclosure of verification sources
#1545208 RESOLVED Policy Document Issue Opened 2019-04-17 · Closed 2023-02-22 · 67% similar
Sectigo: Missing Changelog in CPS
#1907568 RESOLVED Ca Documents Policy Document Issue Opened 2024-07-12 · Closed 2024-09-06 · 67% similar
NETLOCK: CPS 1.5.2. problem and contact information update
#1717034 RESOLVED Ca Documents Policy Document Issue Opened 2021-06-17 · Closed 2023-02-22 · 67% similar
Asseco DS / Certum: CPS does not refer to BR domain validation methods
#1650234 RESOLVED Ca Documents Policy Document Issue Opened 2020-07-02 · Closed 2023-02-22 · 66% similar
PKIoverheid / QuoVadis: CPS inconsistencies
#1509002 RESOLVED Policy Document Issue Incident Opened 2018-11-21 · Closed 2023-02-22 · 66% similar
Camerfirma: MULTICERT certificates with a validity period greater than 825 days
#1688215 RESOLVED Ca Documents Incident Policy Document Issue Opened 2021-01-22 · Closed 2023-02-22 · 65% similar
Camerfirma: CP/CPS of Intesa Sanpaolo Sub-CA is Non-Compliant

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action