MULTICERT misissuance and audit coverage gaps
This case concerns MULTICERT certificates that were reported as misissued because the qcStatements extension contained an invalid UTF8String value. The initial report also raised a CCADB audit-scope problem for the issuer "MULTICERT SSL Certification Authority 001," and later discussion identified audit coverage questions for two other Camerfirma sub-CAs, InfoCert Organization Validation CA 3 and Intesa Sanpaolo Organization Validation CA. Camerfirma/MULTICERT responded by providing an incident report, audit attestation letters, problematic-certificate lists, and later audit memos intended to cover the disputed period. Mozilla reviewers questioned whether the supplied audit documents satisfied Mozilla policy and BR audit-period requirements, and asked for clearer auditor confirmation. By the end of the thread, Camerfirma said the audit gap had been covered by additional memos and that the related non-conformities had been solved, while Wayne Thayer summarized the misissuance and audit issues and indicated the bug could be resolved in the context of other Camerfirma issues.
- A MULTICERT certificate was reported as misissued due to an invalid qcStatements UTF8String value.
- Camerfirma posted an incident report describing remediation steps for the misissuance and audit publication issues.
- Camerfirma provided auditor attestation statements and audit memos for InfoCert Organization Validation CA 3 and Intesa Sanpaolo Organization Validation CA.
- Camerfirma said the previously missing audit period had been audited and that the auditor issued memos covering it.
- Mozilla summarized the case as involving 174 misissued certificates, an audit-scope issue for MULTICERT SSL Certification Authority 001, and audit gaps for two other sub-CAs.
- Fastly representative — Wayne Thayer reported a misissued MULTICERT certificate and asked Camerfirma to file an incident report and explain the audit-scope discrepancy.
- AC Camerfirma, S.A. — Camerfirma posted an incident report listing corrective actions, including stopping issuance, fixing and testing code, reissuing affected certificates, and revoking test certificates.
- Fastly representative — Wayne Thayer questioned the audit attestation letter’s fingerprint, audit period, and whether another audit was needed.
- AC Camerfirma, S.A. — Camerfirma said MULTICERT would include the previously missing audit period in the upcoming audit.
- Fastly representative — Wayne Thayer said a late audit would not fix the problem and suggested revoking the MULTICERT SSL Certification Authority 001 and creating a new one.
- Fastly representative — Wayne Thayer said the MULTICERT SSL Certification Authority 001 cross-certificate changed his view of the audit statement, but noted corrected audit statements were still needed for inclusion request bug 1040072.
- AC Camerfirma, S.A. — Camerfirma said it was updating CCADB audits for GLOBAL CORPORATE SERVER and attached new audit documents.
- AC Camerfirma, S.A. — Camerfirma said the December 2018 audit covered certificates issued since the sub-CAs started operating in September 2017 and attached the relevant certification documents.
- AC Camerfirma, S.A. — Camerfirma said there was a gap in the initially published reports, but the period had been audited and the auditor issued memos covering it.
- Fastly representative — Wayne Thayer summarized the misissuance and audit issues and said he did not expect further progress.