← AC Camerfirma, S.A. cases
Bugzilla #1556806
Certificate Misissuance
Self Reported Incident
Camerfirma: Infocert misissued certificates
RESOLVED
FIXED
AC Camerfirma, S.A.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
Camerfirma, S.A. disclosed a compliance failure involving misissued certificates by its subCA, Infocert. The issues were identified by Camerfirma's Quality Control Team during routine checks, revealing a wrong DNS name in the Subject Alternative Name (SAN) and an organizational unit name that was too long. The misissued certificates were detected and revoked promptly, with corrective actions taken to prevent future occurrences. Camerfirma has since implemented additional pre-issuance checks and improved oversight of its subCAs to enhance compliance with Mozilla's policies.
Chronology
- Camerfirma detected a misissued certificate with a wrong DNS name in SAN.
- Camerfirma detected a misissued certificate with an organizational unit name that was too long.
- Camerfirma filed a bug report to disclose the misissuance incidents.
- All addendums to contracts with subCAs were signed.
Thread Activity
- AC Camerfirma, S.A. — Camerfirma reported the misissued certificates and outlined the corrective actions taken.
- Community commenter — Requested clarification on the timing of the report and the steps taken to prevent future issues.
- AC Camerfirma, S.A. — Detailed the new requirements for existing and new subCAs to improve oversight and compliance.
- AC Camerfirma, S.A. — Confirmed that all addendums to contracts with subCAs were signed.
Participants
AC Camerfirma, S.A.
Community commenter
Fastly representative
External References
Similar Local Cases
Camerfirma: certificate for unregistered domain cuatis.net
Camerfirma: suspicious certificate for com.com
Camerfirma: Failure to abide by Section 8 of Mozilla Policy: Unauthorized, improperly disclosed Subordinate CA
Camerfirma: Multicert SSL CA 001: Insufficient serial number entropy
Camerfirma: Outdated audit statements for intermediate certs
Camerfirma: Intesa Sanpaolo misissued certificates
Camerfirma: Govern d'Andorra audits
Camerfirma: Invalid authorityKeyIdentifier, violating Mozilla Policy and RFC 5280