← Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) cases
Bugzilla #1696872
Certificate Misissuance
FNMT: Missisuance of web site certificates without CA/Browser Forum’s reserved policy OID
RESOLVED
FIXED
Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT)
AI Summary
The Government of Spain's FNMT identified a misissuance of web certificates lacking the required CA/Browser Forum reserved policy OIDs. This issue was discovered on March 8, 2021, leading to the suspension of certificate issuance for affected types. FNMT promptly initiated a revocation process for 488 certificates and updated their certificate profiles. All affected certificates were revoked by March 13, 2021, and a new compliance protocol was established to prevent future occurrences.
Chronology
- Identification of noncompliance issue and suspension of certificate issuance.
- Notification process to subscribers initiated.
- All affected certificates revoked.
Participants
alain@fnmt.es
bwilson@mozilla.com
External References
Similar Local Cases
GoDaddy: Misissuance of Cross Signed Certs
HARICA: S/MIME certificate issuance with incorrect commonName
FNMT: LDAP URI in CRL Distribution Points Extension
FNMT: OU exceeds 64 characters
GDCA: Issuance of SSL/TLS certificates with Non-critical Basic Constraints
FNMT: Issuance of certificate using keys previously reported as compromised
Sectigo: Subject field with unvalidated information included in certificates
SwissSign: EV code in JurisdiktionStateOrProvinceName