Camerfirma: certificate with an incorrect OrganizationName (misissuance)
Camerfirma reported that its quality control detected a TLS certificate with an incorrectly filled OrganizationName field. The issue was identified on 2020-11-27 morning (with a later note that it was detected on 2020-11-30 morning) and Camerfirma confirmed the problem and began investigation. The CA stated the error was an isolated case affecting 1 certificate, and that it revoked the old certificate on 2020-11-30 afternoon. In its response, Camerfirma explained that the backoffice operated by its Validation Team presents registration data as “label: value”, and that the validation officer did not notice the incorrect value in the Organization field. Camerfirma shared remediation steps including updating the backoffice interface to visually distinguish labels from values, and it also changed the validation regex to further restrict occurrences of special characters. The UI enhancement and regex change were deployed on 2021-01-26, and the thread indicates there were no more planned actions, with Mozilla planning to close the bug on or after 2021-02-12.
- Camerfirma reported an incorrect OrganizationName value in a TLS certificate to Mozilla/CA Program.
- Camerfirma revoked the affected certificate after confirming the issue.
- Camerfirma deployed a backoffice UI enhancement and updated validation regex to further restrict special characters.
- AC Camerfirma, S.A. — Camerfirma reported that quality control detected a certificate with an incorrectly filled Organization field and said it was revoked on 2020-11-30 afternoon, linking to the crt.sh entry.
- AC Camerfirma, S.A. — Camerfirma corrected the timeline, stating the wrong organization name was detected on 2020-11-27 morning.
- MULTICERT — CA Forum posted the misissuance report details, including that the Organization DN field contained a wrong prefix `: ` and describing Camerfirma’s awareness, investigation, and remediation plan.
- MULTICERT — CA Forum provided a status update that the planned UI change was targeted for deployment on 2021-01-28.
- MULTICERT — CA Forum stated they were on track for the 2021-01-28 deployment.
- MULTICERT — CA Forum repeated the status update that they were on track for 2021-01-28.
- MULTICERT — CA Forum repeated the status update that they were on track for 2021-01-28.
- MULTICERT — CA Forum reported the fix was deployed: the UI was enhanced to distinguish labels and values, and the validation regex was changed to restrict special characters.
- MULTICERT — CA Forum stated there were no more planned actions and suggested closing if no further questions.
- Mozilla representative — Mozilla stated it would close the bug on or after 2021-02-12 unless it should remain open.