Camerfirma: certificate for unregistered domain cuatis.net (mail.cuatis.net typo)
Camerfirma issued a certificate for the domain mail.cuatis.net, where the subject organization was listed as "CUALTIS S.L.U". On the same day, the certificate was revoked and Camerfirma issued a replacement certificate for mail.cualtis.net (adding an "l"), after which Camerfirma stated that cuatis.net is not a registered domain. The bug was opened externally by Andrew Ayer, and Camerfirma reported that it became aware of the problem on October 22, 2020 because of that bug. Camerfirma said it verified that the certificate was issued with an error in its domain name, investigated why it was possible to issue the incorrect certificate, and reviewed the controls in place at the time. Camerfirma stated that the incorrect certificate was the only one issued with that problem and that it was revoked immediately after detection; it also described remediation steps including new automatic controls (domain syntax control and CAA verification) and reinforcement/training updates for RA operators, plus a planned functionality to detect suspicious revocations. The thread includes an update that the deployed controls (domain syntax control and automatic CAA verification) are intended to avoid future problems, with the additional revocation-detection functionality planned for development by March 2021. Mozilla indicated it would schedule closure on or about 22-Jan-2021 unless further issues needed to be addressed in the bug thread.
- Camerfirma issued a certificate for mail.cuatis.net, revoked it, and issued a replacement for mail.cualtis.net the same day.
- A bug was opened externally reporting the certificate issue.
- Camerfirma began investigating after becoming aware of the bug and reviewed issuance controls and remediation steps.
- Camerfirma reported deployed controls and training updates, and stated a revocation-detection functionality would be developed by March 2021.
- Mozilla indicated it would schedule closure on or about 22-Jan-2021 unless further bug-thread-specific issues remained.
- Camerfirma stated it had no further updates to add.
- Mm representative — Reported that Camerfirma issued a certificate for mail.cuatis.net and then revoked it and issued a replacement for mail.cualtis.net, noting cuatis.net is not a registered domain and asking for validation details.
- AC Camerfirma, S.A. — Provided an incident report describing how Camerfirma became aware (via bug 1672423), its investigation steps, why the error occurred, and remediation including new automatic controls and RA training reinforcement.
- Community commenter — Questioned Camerfirma’s assurance about not issuing further problematic certificates and criticized the incident explanation and proposed training as insufficient for baseline expectations.
- AC Camerfirma, S.A. — Responded that Camerfirma examined issued certificates, described additional controls and alerting around suspicious revocations, and stated plans to examine other root causes and review organizational responsibilities.
- AC Camerfirma, S.A. — Updated that syntax control of the domain and automatic verification of CAA are deployed, training was updated, and the revocation-detection functionality would be developed by March 2021.
- Community commenter — Suggested moving further discussion to the mozilla.dev.security.policy thread rather than continuing in the bug.
- AC Camerfirma, S.A. — Asked whether extra information about the bug was needed for closure, noting the linked discussion was general.
- Mozilla representative — Stated Mozilla would schedule closure on or about 22-Jan-2021 unless further bug-thread-specific issues needed addressing.
- AC Camerfirma, S.A. — Confirmed there were no more updates to add.