← AC Camerfirma, S.A. cases
Bugzilla #1524871
Certificate Misissuance
Camerfirma: failure to revoke underscores
RESOLVED
FIXED
AC Camerfirma, S.A.
AI Summary
Camerfirma failed to revoke three certificates containing dnsNames with underscores by the required deadline of January 15, 2019. After being notified of the oversight, they revoked two certificates promptly, while one remained unrevoked until February 4, 2019. An incident report was generated, detailing the steps taken to prevent future occurrences, including the implementation of application controls to avoid issuing certificates with prohibited characters. The issue has since been resolved, and the necessary linting service is now operational.
Chronology
- Notification sent to Camerfirma about unrevoked certificates.
- Final unrevoked certificate was revoked.
- Camerfirma's lint service became available.
Participants
Jonathan Rudenberg
Eusebio Herrera
Wayne Thayer
Ryan Sleevi
Martin Ja
External References
Similar Local Cases
Camerfirma: Infocert misissued certificates
Camerfirma: Intesa Sanpaolo misissued certificates
Camerfirma: MULTICERT Misissuance and missing audits
Telia: Misissued certificate - invalid dnsName
Camerfirma: MULTICERT Misissuance and missing audits
Camerfirma: Missing audit for Intermediate certificate
SECOM: Failure to disclose Unconstrained Intermediate within 7 Days
Hongkong Post / Certizen: Failure to report misissuance