Camerfirma: Invalid authorityKeyIdentifier, violating Mozilla Policy and RFC 5280
Camerfirma discovered that it had issued approximately 3233 certificates with an invalid Authority Key Identifier, violating both Mozilla Policy and RFC 5280. The issue was identified during an evaluation of linting tools, prompting the CA to proactively disclose the misissuance to Mozilla. In response, Camerfirma developed an action plan to rectify the issue, which included ensuring that all new certificates would only include the key identifier in the Authority Key Identifier field. By October 29, 2019, all website certificates were updated accordingly, and S/MIME certificates were set to be updated by November 20, 2019. The bug was resolved with the implementation of these changes.
- Camerfirma discovers misinterpretation of Authority Key Identifier and reports to Mozilla.
- Camerfirma confirms all website certificates now comply with the correct Authority Key Identifier.
- Camerfirma updates all S/MIME certificates to comply with the correct Authority Key Identifier.
- Community commenter — Reported that Camerfirma issued certificates violating RFC 5280 and Mozilla Policy.
- AC Camerfirma, S.A. — Camerfirma acknowledges the issue and outlines an action plan to resolve it.
- AC Camerfirma, S.A. — Camerfirma confirms that changes to the Authority Key Identifier will be deployed soon.
- AC Camerfirma, S.A. — Camerfirma states that all new S/MIME certificates now include the correct Authority Key Identifier.