← AC Camerfirma, S.A. cases
Bugzilla #1623384
Certificate Problem Report
Camerfirma: Invalid authorityKeyIdentifier - recurrent incident
RESOLVED
FIXED
AC Camerfirma, S.A.
AI Summary
Camerfirma faced a recurrent issue with invalid authorityKeyIdentifiers in their certificates. The problem was first identified in March 2020, leading to the revocation of 37 affected certificates. The CA implemented a series of corrective actions, including updating their profile management procedures and introducing new controls to prevent future occurrences. Despite initial challenges in detecting the issue, Camerfirma has since taken steps to improve their compliance and operational processes.
Chronology
- Last certificate with the problem issued.
- Two problematic pre-certificates revoked.
- All affected certificates revoked.
- New control for authorityKeyIdentifier verification implemented.
Participants
Ana Lopes
Wayne Thayer
Ryan Sleevi
Ben Wilson
External References
Similar Local Cases
Camerfirma: Invalid authorityKeyIdentifier - recurrent incident
Camerfirma: BR revocation period exceeded
Camerfirma: Unrevocation of MULTICERT SSL Certification Authority 001 certificate
Camerfirma: Failure to revoke within 7 days: OCSP EKU issue
Camerfirma: MULTICERT certificates with a validity period greater than 825 days
Camerfirma: Unrevocation of MULTICERT SSL Certification Authority 001 certificate
Camerfirma: certificate for unregistered domain cuatis.net
Camerfirma: Invalid stateOrProvinceName field