← Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) cases
Bugzilla #1596949 Ca Documents Policy Document Issue Self Reported Incident

FNMT: CP/CPS lack CAA processing details

RESOLVED FIXED Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns FNMT’s Certificate Policy/Certification Practice Statements (CP/CPS) not explicitly stating the CA’s CAA processing practice required by Mozilla Baseline Requirements. The issue was identified by FNMT during an internal documentary self-audit, which found that two CPS documents lacked an explicit reference to the Issuer Domain Names recognized by the FNMT CAs in CAA “issue” records. FNMT stated that the omission was due to a transcription error between CPS draft versions and that no certificates were issued without CAA record checking. FNMT then modified and published updated CPS versions to include the explicit set of Issuer Domain Names, and provided links to the approved new CPS documents. A reviewer requested a full incident report and later noted the incident report did not inspire much confidence, but the bug was resolved anyway. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 20:17 UTC Revised: 2026-06-16 19:11 UTC Confidence: 0.88 8 comments
Chronology
  1. FNMT disclosed that its CP/CPS documents lacked required CAA processing details about recognized Issuer Domain Names.
  2. FNMT published approved CPS updates adding the explicit Issuer Domain Names recognized for CAA “issue” records.
  3. FNMT provided an incident report describing how the issue was discovered and corrected.
  4. A reviewer agreed the incident report was lacking but resolved the bug.
Thread Activity
  1. Community commenter — Andrew Ayer reported that FNMT’s CP/CPS for specific documents lacked any mention of CAA processing in the required section and did not specify the Issuer Domain Names.
  2. Community commenter — Ryan Sleevi asked for more details and an incident response analyzing root cause, and requested confirmation of contact information.
  3. Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — Alain stated FNMT had identified the lack and would modify the CPS in the next days, and noted the primary PoC contact needed updating.
  4. Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — Alain provided links to approved new CPS versions that explicitly include the set of Issuer Domain Names recognized in CAA “issue” records.
  5. Fastly representative — Wayne requested a full incident report as described in Mozilla’s incident reporting guidance.
  6. Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — Alain provided the incident report stating FNMT discovered the omission during an internal documentary self-audit, that CPS changes were approved and published on November 18, that no certificates were issued without CAA record checking, and that the failure was due to a transcription error.
  7. Community commenter — Ryan commented that the incident report lacked confidence and suggested closing the case.
  8. Fastly representative — Wayne agreed the incident report was lacking but resolved the bug, stating he did not expect a more meaningful response.
Participants
Mm representative Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) Community commenter Fastly representative
Similar Local Cases
#1705480 RESOLVED Ca Documents Policy Document Issue Opened 2021-04-15 · Closed 2023-02-22 · 87% similar
SECOM: CP/CPS does not clearly specify domain validation methods
#1688215 RESOLVED Ca Documents Incident Policy Document Issue Opened 2021-01-22 · Closed 2023-02-22 · 86% similar
Camerfirma: CP/CPS of Intesa Sanpaolo Sub-CA is Non-Compliant
#2056989 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-07-22 Still Open · 79% similar
FNMT: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy
#1599503 RESOLVED Self Reported Incident Opened 2019-11-26 · Closed 2024-06-30 · 77% similar
TrustCor: No mention of TLS-capable Intermediate CAs in WTBR audit reports
#1560234 RESOLVED Self Reported Incident Opened 2019-06-20 · Closed 2022-11-14 · 77% similar
SECOM: Ambiguity on KeyUsage with ECC public key
#1713976 RESOLVED Policy Document Issue Opened 2021-06-02 · Closed 2023-02-22 · 77% similar
Amazon Trust Services: CP/CPS does not specify key compromise methods
#1548714 RESOLVED Self Reported Incident Opened 2019-05-02 · Closed 2023-02-22 · 76% similar
SECOM: "Default City" in Subject:localityName
#1484766 RESOLVED Self Reported Incident Revocation Issue Security Incident Opened 2018-08-20 · Closed 2024-06-30 · 76% similar
GoDaddy: Random Value Vulnerability in Domain Validation Method

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action