← AC Camerfirma, S.A. cases
Bugzilla #1649944 Certificate Problem Report

Camerfirma: Incorrect OCSP Delegated Responder Certificate

RESOLVED FIXED AC Camerfirma, S.A.
AI Summary

Camerfirma issued OCSP Delegated Responder certificates without the required 'id-pkix-ocsp-nocheck' response, violating Baseline Requirements. The issue was reported by Ryan Sleevi, prompting an investigation by Camerfirma. They confirmed the problem and initiated a remediation plan, including revocation of affected certificates. The situation was critical due to the certificates' role in medical prescriptions in Spain. Although Camerfirma planned to revoke the problematic CA within nine months, concerns were raised about the delay's impact on security.

Model: gpt-4o-mini Generated: 2026-06-13 21:24 UTC Confidence: 0.95
Chronology
  1. Bug reported by Ryan Sleevi.
  2. Camerfirma acknowledged receipt and began investigation.
  3. Camerfirma provided a detailed incident report.
  4. Camerfirma outlined their remediation plan and controls.
  5. Camerfirma confirmed steps to stay informed on CA issues.
Participants
Ryan Sleevi Eusebio Herrera Brett Wilson Ana Lopes
Similar Local Cases
#1652603 RESOLVED Certificate Problem Report Opened 2020-07-13 · Closed 2023-02-22 · 75% similar
Camerfirma: Failure to revoke within 7 days: OCSP EKU issue
#1672423 RESOLVED Certificate Problem Report Opened 2020-10-21 · Closed 2023-02-22 · 74% similar
Camerfirma: certificate for unregistered domain cuatis.net
#1532333 RESOLVED Certificate Problem Report Opened 2019-03-04 · Closed 2023-02-22 · 74% similar
Camerfirma: Unrevocation of MULTICERT SSL Certification Authority 001 certificate
#1672409 RESOLVED Certificate Problem Report Opened 2020-10-21 · Closed 2023-02-22 · 73% similar
Camerfirma: suspicious certificate for com.com
#1667430 RESOLVED Certificate Problem Report Opened 2020-09-25 · Closed 2023-02-22 · 73% similar
Camerfirma: Invalid stateOrProvinceName field
#1685557 RESOLVED Certificate Problem Report Opened 2021-01-07 · Closed 2023-02-22 · 67% similar
Camerfirma: Certificates without CABForum OV Reserved Policy Identifier
#1692533 RESOLVED Certificate Problem Report Opened 2021-02-12 · Closed 2023-02-22 · 66% similar
Camerfirma: Old CAs with an RSA modulus size of 2047 bits
#1509002 RESOLVED Certificate Problem Report Opened 2018-11-21 · Closed 2023-02-22 · 65% similar
Camerfirma: MULTICERT certificates with a validity period greater than 825 days

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action