← AC Camerfirma, S.A. cases
Bugzilla #1649944 Self Reported Incident

Camerfirma: Incorrect OCSP Delegated Responder Certificate

RESOLVED FIXED AC Camerfirma, S.A.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Camerfirma disclosed a compliance issue regarding the issuance of OCSP Delegated Responder Certificates without the required `id-pkix-ocsp-nocheck` response. This issue was initially reported by Ryan Sleevi and triggered an investigation by Camerfirma. They confirmed awareness of the problem upon the bug's opening and provided a timeline of their response actions, including contacting affected CAs and preparing an incident report. Camerfirma plans to revoke the affected certificates and destroy their keys within nine months, pending approval from the Spanish supervisory body. The case is now resolved, with further discussions consolidated under a related bug.

Model: gpt-4o-mini Generated: 2026-06-13 21:24 UTC Revised: 2026-06-16 18:10 UTC Confidence: 0.85 13 comments
Chronology
  1. Camerfirma was made aware of the compliance issue regarding OCSP Delegated Responder Certificates.
  2. Camerfirma submitted an incident report detailing their findings and planned remediation.
  3. The bug was closed, with further discussions directed to a related case.
Thread Activity
  1. Community commenter — Reported the compliance issue regarding OCSP Delegated Responder Certificates.
  2. AC Camerfirma, S.A. — Confirmed receipt of the information and started an investigation.
  3. AC Camerfirma, S.A. — Provided a detailed timeline of actions taken in response to the issue.
  4. Mozilla representative — Closed the bug and directed further discussion to a related case.
Participants
Community commenter AC Camerfirma, S.A. Mozilla representative
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
#1672029 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-10-19 · Closed 2023-02-22 · 100% similar
Camerfirma: Failure to abide by Section 8 of Mozilla Policy: Unauthorized, improperly disclosed Subordinate CA
#1575530 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-08-21 · Closed 2023-02-22 · 100% similar
Camerfirma: Govern d'Andorra audits
#1623384 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-03-18 · Closed 2023-02-22 · 98% similar
Camerfirma: Invalid authorityKeyIdentifier - recurrent incident
#1534429 RESOLVED Incident Self Reported Incident Opened 2019-03-11 · Closed 2023-02-22 · 96% similar
Camerfirma: Multicert SSL CA 001: Insufficient serial number entropy
#1549861 RESOLVED Repository Issue Self Reported Incident Opened 2019-05-07 · Closed 2023-02-22 · 96% similar
Camerfirma: Outdated audit statements for intermediate certs
#1557085 RESOLVED Certificate Misissuance Revocation Issue Self Reported Incident Opened 2019-06-05 · Closed 2023-02-22 · 95% similar
Camerfirma: Intesa Sanpaolo misissued certificates
#1686524 RESOLVED Self Reported Incident Incident Opened 2021-01-13 · Closed 2023-02-22 · 94% similar
Camerfirma: Certificate issued with 3-year lifespan, unknown policy
#1556806 RESOLVED Certificate Misissuance Self Reported Incident Opened 2019-06-04 · Closed 2023-02-22 · 94% similar
Camerfirma: Infocert misissued certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action