← MULTICERT cases
Bugzilla #1532333 Self Reported Incident

Camerfirma: Unrevocation of MULTICERT SSL Certification Authority 001 certificate

RESOLVED FIXED MULTICERT
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Camerfirma reported an incident involving the unrevocation of the MULTICERT SSL Certification Authority 001 certificate. The issue arose when MULTICERT alerted Camerfirma about revocation alerts for this intermediate CA. An investigation revealed that a human error led to confusion between two CA certificates with similar attributes. Camerfirma proposed revoking the incorrect certificate but opted for a rollback due to potential disruptions for customers, particularly in electronic payments. The CA has since implemented several procedural improvements to prevent similar incidents, including enhanced controls for CRL publication and certificate issuance.

Model: gpt-4o-mini Generated: 2026-06-13 18:05 UTC Revised: 2026-06-16 19:11 UTC Confidence: 0.85 21 comments
Chronology
  1. MULTICERT informed Camerfirma about revocation alerts for the CA certificate.
  2. Camerfirma improved CRL publishing procedures.
  3. EJBCA pre-production environment deployment completed.
  4. EJBCA production environment deployment completed.
  5. Camerfirma confirmed the deployment of an internal tool to manage CA certificates.
Thread Activity
  1. AC Camerfirma, S.A. — Camerfirma details the timeline and actions taken in response to the incident.
  2. Community commenter — Highlights the severity of the incident and requests a thorough analysis.
  3. AC Camerfirma, S.A. — Explains the reasons behind the issuance of two certificates and the subsequent errors.
  4. AC Camerfirma, S.A. — Updates on the deployment of an internal tool to manage CA certificates.
  5. Fastly representative — Confirms that all questions have been answered and remediation is complete.
Participants
AC Camerfirma, S.A. Community commenter Fastly representative
External References
Similar Local Cases
#1509002 RESOLVED Self Reported Incident Opened 2018-11-21 · Closed 2023-02-22 · 100% similar
Camerfirma: MULTICERT certificates with a validity period greater than 825 days
#1481862 RESOLVED Self Reported Incident Opened 2018-08-08 · Closed 2023-02-22 · 96% similar
Camerfirma: MULTICERT organizationName Too Long
#1534429 RESOLVED Ca Certificate Compliance Self Reported Incident Incident Certificate Misissuance Opened 2019-03-11 · Closed 2023-02-22 · 94% similar
Camerfirma: Multicert SSL CA 001: Insufficient serial number entropy
#1672409 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2020-10-21 · Closed 2023-02-22 · 85% similar
Camerfirma: suspicious certificate for com.com
#1672029 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-10-19 · Closed 2023-02-22 · 85% similar
Camerfirma: Failure to abide by Section 8 of Mozilla Policy: Unauthorized, improperly disclosed Subordinate CA
#1534429 RESOLVED Incident Self Reported Incident Opened 2019-03-11 · Closed 2023-02-22 · 85% similar
Camerfirma: Multicert SSL CA 001: Insufficient serial number entropy
#1623384 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-03-18 · Closed 2023-02-22 · 85% similar
Camerfirma: Invalid authorityKeyIdentifier - recurrent incident
#1481862 RESOLVED Self Reported Incident Opened 2018-08-08 · Closed 2023-02-22 · 84% similar
Camerfirma: MULTICERT organizationName Too Long

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action