← MULTICERT cases
Bugzilla #1502957 Ca Certificate Compliance Certificate Misissuance

MULTICERT misissuance and audit coverage gaps

RESOLVED FIXED MULTICERT
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns MULTICERT certificates that were reported as misissued because the qcStatements extension contained an invalid UTF8String value. The initial report also raised a CCADB audit-scope problem for the issuer "MULTICERT SSL Certification Authority 001," and later discussion identified audit coverage questions for two other Camerfirma sub-CAs, InfoCert Organization Validation CA 3 and Intesa Sanpaolo Organization Validation CA. Camerfirma/MULTICERT responded by providing an incident report, audit attestation letters, problematic-certificate lists, and later audit memos intended to cover the disputed period. Mozilla reviewers questioned whether the supplied audit documents satisfied Mozilla policy and BR audit-period requirements, and asked for clearer auditor confirmation. By the end of the thread, Camerfirma said the audit gap had been covered by additional memos and that the related non-conformities had been solved, while Wayne Thayer summarized the misissuance and audit issues and indicated the bug could be resolved in the context of other Camerfirma issues.

Model: gpt-5.4-mini Generated: 2026-06-13 17:56 UTC Revised: 2026-06-16 19:10 UTC Confidence: 0.93 38 comments
Chronology
  1. A MULTICERT certificate was reported as misissued due to an invalid qcStatements UTF8String value.
  2. Camerfirma posted an incident report describing remediation steps for the misissuance and audit publication issues.
  3. Camerfirma provided auditor attestation statements and audit memos for InfoCert Organization Validation CA 3 and Intesa Sanpaolo Organization Validation CA.
  4. Camerfirma said the previously missing audit period had been audited and that the auditor issued memos covering it.
  5. Mozilla summarized the case as involving 174 misissued certificates, an audit-scope issue for MULTICERT SSL Certification Authority 001, and audit gaps for two other sub-CAs.
Thread Activity
  1. Fastly representative — Wayne Thayer reported a misissued MULTICERT certificate and asked Camerfirma to file an incident report and explain the audit-scope discrepancy.
  2. AC Camerfirma, S.A. — Camerfirma posted an incident report listing corrective actions, including stopping issuance, fixing and testing code, reissuing affected certificates, and revoking test certificates.
  3. Fastly representative — Wayne Thayer questioned the audit attestation letter’s fingerprint, audit period, and whether another audit was needed.
  4. AC Camerfirma, S.A. — Camerfirma said MULTICERT would include the previously missing audit period in the upcoming audit.
  5. Fastly representative — Wayne Thayer said a late audit would not fix the problem and suggested revoking the MULTICERT SSL Certification Authority 001 and creating a new one.
  6. Fastly representative — Wayne Thayer said the MULTICERT SSL Certification Authority 001 cross-certificate changed his view of the audit statement, but noted corrected audit statements were still needed for inclusion request bug 1040072.
  7. AC Camerfirma, S.A. — Camerfirma said it was updating CCADB audits for GLOBAL CORPORATE SERVER and attached new audit documents.
  8. AC Camerfirma, S.A. — Camerfirma said the December 2018 audit covered certificates issued since the sub-CAs started operating in September 2017 and attached the relevant certification documents.
  9. AC Camerfirma, S.A. — Camerfirma said there was a gap in the initially published reports, but the period had been audited and the auditor issued memos covering it.
  10. Fastly representative — Wayne Thayer summarized the misissuance and audit issues and said he did not expect further progress.
Participants
Fastly representative AC Camerfirma, S.A. Community commenter Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1502957 RESOLVED Certificate Misissuance Incident Opened 2018-10-29 · Closed 2023-02-22 · 98% similar
Camerfirma: MULTICERT Misissuance and missing audits
#1600114 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-11-28 · Closed 2023-02-22 · 92% similar
Camerfirma: EV Certificates issued with wrong Business Category
#988633 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2014-03-26 · Closed 2023-02-22 · 87% similar
GoDaddy: improperly encoded certificate issued by Go Daddy Secure Certification Authority
#1586792 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-10-07 · Closed 2023-02-22 · 86% similar
QuoVadis: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy or the BRs
#1600301 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-11-29 · Closed 2023-02-22 · 86% similar
Asseco DS / Certum: EV Certificates issued with wrong Business Category
#1369359 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-06-01 · Closed 2023-02-22 · 85% similar
StartCom: mis-issuance of certs with unvalidated domain names and bogus field values
#1590810 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-10-23 · Closed 2023-02-22 · 85% similar
Sectigo: EV SSL Certificates with incorrect businessCategory
#1456655 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2018-04-24 · Closed 2023-02-22 · 85% similar
DigiCert / ABB: Issues with DN, country code and keyUsage

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action