← Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) cases
Bugzilla #1495507
Certificate Misissuance
FNMT: OU exceeds 64 characters
RESOLVED
FIXED
Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT)
AI Summary
The Government of Spain's CA, FNMT, misissued 103 certificates with an Organizational Unit (OU) field exceeding the maximum length of 64 characters. The issue was identified on October 1, 2018, and an incident report was requested. FNMT took immediate action, including stopping the issuance of such certificates and developing automated validation controls. By October 26, 2018, they had implemented measures to prevent future occurrences and added the misissued certificates to Certificate Transparency logs. The case has been resolved with all necessary updates completed.
Chronology
- Issue identified and incident report requested.
- Investigation confirmed misissued certificates.
- Automated validation control implemented.
- Production environment upgraded with new validation component.
Participants
Wayne Thayer
Rafa Medina
External References
Similar Local Cases
FNMT: LDAP URI in CRL Distribution Points Extension
FNMT: Missisuance of web site certificates without CA/Browser Forum’s reserved policy OID
DigiCert: "Some-State" in stateOrProvinceName
NetLock: CN not in SAN
GoDaddy: Improper DER results in failure to comply with RFC 5280 - Invalid characters in PrintableString
Camerfirma: MULTICERT organizationName Too Long
FNMT: Issuance of certificate using keys previously reported as compromised
IdenTrust: Improper encoding of wildcard certificate