← AC Camerfirma, S.A. cases
Bugzilla #1586860
Certificate Problem Report
Camerfirma: Invalid authorityKeyIdentifier, violating Mozilla Policy and RFC 5280
RESOLVED
FIXED
AC Camerfirma, S.A.
AI Summary
Camerfirma was found to have issued certificates that violated the requirements of RFC 5280 and Mozilla Policy regarding the Authority Key Identifier. Specifically, approximately 3233 certificates included both a key identifier and an issuer name with serial number, which is prohibited. The CA acknowledged the misinterpretation of the policy and developed an action plan to rectify the issue, committing to issue certificates with only the key identifier moving forward. The problem was resolved, and all new certificates issued since late 2019 comply with the updated requirements.
Chronology
- Bug reported by Ryan Sleevi regarding invalid authorityKeyIdentifier.
- Camerfirma acknowledges misinterpretation and commits to corrective actions.
- Modification to issue compliant certificates deployed.
- All new S/MIME certificates issued with compliant Authority Key Identifier.
- New Mozilla Policy requiring revocation of non-compliant certificates takes effect.
- Incident report filed for recurrence of the problem.
Participants
Ryan Sleevi
Juan Angel Martin
Wayne Thayer
Ramiro
External References
Similar Local Cases
Camerfirma: Unrevocation of MULTICERT SSL Certification Authority 001 certificate
Camerfirma: Invalid stateOrProvinceName field
Camerfirma: Invalid authorityKeyIdentifier - recurrent incident
Camerfirma: Non-BR-Compliant OCSP Responders
Camerfirma: MULTICERT certificates with a validity period greater than 825 days
Camerfirma: BR revocation period exceeded
Camerfirma: Unrevocation of MULTICERT SSL Certification Authority 001 certificate
Microsoft PKI Services: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy