Camerfirma: Decision not to revoke certificates with authorityKeyIdentifier that violates Mozilla Policy
The bug records a decision regarding Camerfirma certificates that contain an authorityKeyIdentifier violating Mozilla policy section 5.2. In a prior determination (bug 1586860), it was found that SSL and S/MIME certificates issued by Camerfirma before Oct 29, 2019 and Nov 18, 2019 respectively contain this authorityKeyIdentifier issue. The reporter stated this bug is intended to record that these certificates were not revoked, noting they were issued prior to a Mozilla policy update that required revocation of certificates violating Mozilla policy. Camerfirma responded that it developed a revocation plan aligned with CA/B Forum and Root Program policy requirements, including effective revocation timelines of 24 hours or 5 days depending on the case. The plan described steps for locating affected certificates, communicating with affected clients/subscribers, and performing effective revocation using a tool that supports CRL generation and OCSP service. The thread concludes with a statement that remediation is complete.
- Mozilla CA Program bug was opened to document that certain Camerfirma certificates were not revoked despite violating Mozilla policy authorityKeyIdentifier requirements.
- Camerfirma provided details of its revocation plan and tooling for handling affected certificates and meeting revocation deadlines.
- The reporter indicated that remediation questions were answered and remediation was complete.
- Fastly representative — Wayne Thayer explained that certificates issued before the Mozilla policy update contain an authorityKeyIdentifier violating Mozilla policy section 5.2 and that this bug records that they were not revoked, asking what Camerfirma is doing to ensure revocation can occur if a similar problem happens under the updated policy.
- AC Camerfirma, S.A. — Ana Lopes stated that AC Camerfirma developed a revocation plan with 24-hour/5-day effective revocation timelines, described process steps (locate, communicate, revoke), and noted tooling for CRL/OCSP plus an upgrade phase to incorporate incident and substitution information.
- Fastly representative — Wayne Thayer said it appears all questions were answered and remediation is complete.