← AC Camerfirma, S.A. cases
Bugzilla #1586860 Ca Certificate Compliance Self Reported Incident

Camerfirma: Invalid authorityKeyIdentifier, violating Mozilla Policy and RFC 5280

RESOLVED FIXED AC Camerfirma, S.A.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Camerfirma discovered that it had issued approximately 3233 certificates with an invalid Authority Key Identifier, violating both Mozilla Policy and RFC 5280. The issue was identified during an evaluation of linting tools, prompting the CA to proactively disclose the misissuance to Mozilla. In response, Camerfirma developed an action plan to rectify the issue, which included ensuring that all new certificates would only include the key identifier in the Authority Key Identifier field. By October 29, 2019, all website certificates were updated accordingly, and S/MIME certificates were set to be updated by November 20, 2019. The bug was resolved with the implementation of these changes.

Model: gpt-4o-mini Generated: 2026-06-13 20:02 UTC Revised: 2026-06-16 18:09 UTC Confidence: 0.90 21 comments
Chronology
  1. Camerfirma discovers misinterpretation of Authority Key Identifier and reports to Mozilla.
  2. Camerfirma confirms all website certificates now comply with the correct Authority Key Identifier.
  3. Camerfirma updates all S/MIME certificates to comply with the correct Authority Key Identifier.
Thread Activity
  1. Community commenter — Reported that Camerfirma issued certificates violating RFC 5280 and Mozilla Policy.
  2. AC Camerfirma, S.A. — Camerfirma acknowledges the issue and outlines an action plan to resolve it.
  3. AC Camerfirma, S.A. — Camerfirma confirms that changes to the Authority Key Identifier will be deployed soon.
  4. AC Camerfirma, S.A. — Camerfirma states that all new S/MIME certificates now include the correct Authority Key Identifier.
Participants
Community commenter AC Camerfirma, S.A. Fastly representative
Similar Local Cases
#1672029 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-10-19 · Closed 2023-02-22 · 100% similar
Camerfirma: Failure to abide by Section 8 of Mozilla Policy: Unauthorized, improperly disclosed Subordinate CA
#1481862 RESOLVED Self Reported Incident Opened 2018-08-08 · Closed 2023-02-22 · 100% similar
Camerfirma: MULTICERT organizationName Too Long
#1556806 RESOLVED Certificate Misissuance Self Reported Incident Opened 2019-06-04 · Closed 2023-02-22 · 100% similar
Camerfirma: Infocert misissued certificates
#1557085 RESOLVED Certificate Misissuance Revocation Issue Self Reported Incident Opened 2019-06-05 · Closed 2023-02-22 · 100% similar
Camerfirma: Intesa Sanpaolo misissued certificates
#1575530 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-08-21 · Closed 2023-02-22 · 100% similar
Camerfirma: Govern d'Andorra audits
#1623384 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-03-18 · Closed 2023-02-22 · 100% similar
Camerfirma: Invalid authorityKeyIdentifier - recurrent incident
#1672409 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2020-10-21 · Closed 2023-02-22 · 97% similar
Camerfirma: suspicious certificate for com.com
#1534429 RESOLVED Incident Self Reported Incident Opened 2019-03-11 · Closed 2023-02-22 · 97% similar
Camerfirma: Multicert SSL CA 001: Insufficient serial number entropy

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action