Camerfirma: MULTICERT organizationName Too Long
This case involves MULTICERT, which discovered that it had issued five certificates with an organizationName field exceeding the allowed length, violating X.509 standards. The issue was detected on August 3, 2018, during a routine check of certificates. In response, MULTICERT revoked the problematic certificates on the same day and suspended further certificate issuance until operational controls were implemented. The CA has since added technical controls to prevent future occurrences and has begun monitoring issued certificates for compliance. The case is now resolved, with all remediation actions completed.
- MULTICERT detected five certificates with organizationName too long and initiated revocation.
- All identified certificates were revoked.
- Camerfirma deployed a post-issuance linting tool.
- Pre-issuance linting was implemented.
- Fastly representative — Juan posted the incident report detailing the discovery of the misissued certificates.
- AC Camerfirma, S.A. — Confirmed that the technical control was deployed on August 14.
- AC Camerfirma, S.A. — Apologized for the delay in responding to questions regarding the technical controls.
- Fastly representative — Confirmed that all remediation actions have been completed.