FNMT: CP/CPS lack CAA processing details
This case concerns FNMT’s Certificate Policy/Certification Practice Statements (CP/CPS) not explicitly stating the CA’s CAA processing practice required by Mozilla Baseline Requirements. The issue was identified by FNMT during an internal documentary self-audit, which found that two CPS documents lacked an explicit reference to the Issuer Domain Names recognized by the FNMT CAs in CAA “issue” records. FNMT stated that the omission was due to a transcription error between CPS draft versions and that no certificates were issued without CAA record checking. FNMT then modified and published updated CPS versions to include the explicit set of Issuer Domain Names, and provided links to the approved new CPS documents. A reviewer requested a full incident report and later noted the incident report did not inspire much confidence, but the bug was resolved anyway. The bug is marked RESOLVED with resolution FIXED.
- FNMT disclosed that its CP/CPS documents lacked required CAA processing details about recognized Issuer Domain Names.
- FNMT published approved CPS updates adding the explicit Issuer Domain Names recognized for CAA “issue” records.
- FNMT provided an incident report describing how the issue was discovered and corrected.
- A reviewer agreed the incident report was lacking but resolved the bug.
- Community commenter — Andrew Ayer reported that FNMT’s CP/CPS for specific documents lacked any mention of CAA processing in the required section and did not specify the Issuer Domain Names.
- Community commenter — Ryan Sleevi asked for more details and an incident response analyzing root cause, and requested confirmation of contact information.
- Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — Alain stated FNMT had identified the lack and would modify the CPS in the next days, and noted the primary PoC contact needed updating.
- Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — Alain provided links to approved new CPS versions that explicitly include the set of Issuer Domain Names recognized in CAA “issue” records.
- Fastly representative — Wayne requested a full incident report as described in Mozilla’s incident reporting guidance.
- Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — Alain provided the incident report stating FNMT discovered the omission during an internal documentary self-audit, that CPS changes were approved and published on November 18, that no certificates were issued without CAA record checking, and that the failure was due to a transcription error.
- Community commenter — Ryan commented that the incident report lacked confidence and suggested closing the case.
- Fastly representative — Wayne agreed the incident report was lacking but resolved the bug, stating he did not expect a more meaningful response.