← Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) cases
Bugzilla #1544586
Ca Certificate Compliance
FNMT: Findings in 2019 Audit Statement, including domain validation methods, CAA, etc.
RESOLVED
FIXED
Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
This case tracks the resolution of findings identified in the 2019 audit of the Government of Spain's CA, FNMT. The audit revealed issues with domain validation methods, including inadequate checks and reliance on outdated information. FNMT acknowledged these findings and provided a timeline of corrective actions, including the elimination of non-compliant validation methods and the implementation of new controls for domain validation and CAA record checks. The CA has since completed the revalidation of affected certificates and updated its procedures to ensure compliance with Mozilla's policies.
Chronology
- Audit findings reported regarding domain validation and CAA compliance.
- Revalidation of all affected certificates completed.
Thread Activity
- Mozilla representative — This bug is to track resolution to the items that were identified as 'findings' in this CA's 2019 audit statement.
- Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — FNMT became aware of the problem via the periodic Audit conducted between January 21st and February 6th, 2019.
- Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — We have been able to complete the revalidation for all the 20 certificates affected.
- Fastly representative — It appears that all questions have been answered and remediation is complete.
Participants
Mozilla representative
Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT)
Fastly representative
Community commenter
External References
Similar Local Cases
DocuSign/Keynectis: Non-BR-Compliant OCSP Responders
Disig: Non-BR-Compliant Certificate Issuance
Firmaprofesional: Non-BR-Compliant OCSP Responders
NetLock: Non-BR-Compliant Certificate Issuance
NetLock: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy
Camerfirma: Govern d'Andorra audits
FNMT: Certificates issued included Policy qualifiers other than id-qt-cps
DigiCert: Failure to properly encode Subject name