← Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) cases
Bugzilla #1693304 Certificate Problem Report

FNMT: Issuance of QCP-n certificates without verifying identity

RESOLVED FIXED Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT)
AI Summary

The Government of Spain's FNMT reported an incident regarding the issuance of QCP-n certificates without proper identity verification. Due to COVID-19 restrictions, the process for verifying identities was compromised, leading to potential non-compliance with Spanish law. The FNMT identified the issue during an audit and suspended the issuance of certificates under the affected procedure. They communicated with the relevant authorities to disable the procedure and initiated corrective actions. The incident did not imply a significant security breach but raised concerns about compliance with legal requirements.

Model: gpt-4o-mini Generated: 2026-06-13 21:11 UTC Confidence: 0.90
Chronology
  1. New procedure implemented for certificate issuance.
  2. Incident detected during annual audit; issuance service suspended.
  3. Potential incident fully diagnosed.
  4. Incident reported publicly.
Participants
alain@fnmt.es pfuentes@wisekey.com ryan.sleevi@gmail.com pablo@anf.es bwilson@mozilla.com
External References
Similar Local Cases
#1744722 RESOLVED Certificate Problem Report Opened 2021-12-07 · Closed 2023-02-22 · 66% similar
FNMT: Invalid localityName
#1659316 RESOLVED Certificate Problem Report Opened 2020-08-16 · Closed 2023-02-22 · 57% similar
Apple: EV Certificate Approver Authorization
#1722089 RESOLVED Certificate Problem Report Opened 2021-07-23 · Closed 2023-02-22 · 56% similar
SSL.com: Issuance of 3 EV TLS certificates without 2-person validation of the organization information
#1639798 RESOLVED Certificate Problem Report Opened 2020-05-21 · Closed 2023-02-22 · 55% similar
GoDaddy: Failure to revoke key-compromised certificates within 24 hours
#1719916 RESOLVED Certificate Problem Report Opened 2021-07-09 · Closed 2023-02-22 · 55% similar
SSL.com: Issuance of an EV TLS certificate with incorrect O Field Value
#1639804 RESOLVED Certificate Problem Report Opened 2020-05-21 · Closed 2023-02-22 · 55% similar
Sectigo: Failure to revoke key-compromised certificate within 24 hours
#1717046 RESOLVED Certificate Problem Report Opened 2021-06-17 · Closed 2022-11-14 · 55% similar
Sectigo: potentially invalid organizational validation certificates
#1598807 RESOLVED Certificate Problem Report Opened 2019-11-23 · Closed 2023-02-22 · 55% similar
IdenTrust: Undisclosed Unrevoked ICAs

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action