Camerfirma: Unrevocation of MULTICERT SSL Certification Authority 001 certificate
Camerfirma reported an incident involving the unrevocation of the MULTICERT SSL Certification Authority 001 certificate. The issue arose when MULTICERT alerted Camerfirma about revocation alerts for this intermediate CA. An investigation revealed that a human error led to confusion between two CA certificates with similar attributes. Camerfirma proposed revoking the incorrect certificate but opted for a rollback due to potential disruptions for customers, particularly in electronic payments. The CA has since implemented several procedural improvements to prevent similar incidents, including enhanced controls for CRL publication and certificate issuance.
- MULTICERT informed Camerfirma about revocation alerts for the CA certificate.
- Camerfirma improved CRL publishing procedures.
- EJBCA pre-production environment deployment completed.
- EJBCA production environment deployment completed.
- Camerfirma confirmed the deployment of an internal tool to manage CA certificates.
- AC Camerfirma, S.A. — Camerfirma details the timeline and actions taken in response to the incident.
- Community commenter — Highlights the severity of the incident and requests a thorough analysis.
- AC Camerfirma, S.A. — Explains the reasons behind the issuance of two certificates and the subsequent errors.
- AC Camerfirma, S.A. — Updates on the deployment of an internal tool to manage CA certificates.
- Fastly representative — Confirms that all questions have been answered and remediation is complete.