← Autoridad de Certificacion Firmaprofesional cases
Bugzilla #1700145
Certificate Problem Report
Firmaprofesional: incorrect reserved CA/B Forum OIDs in certificates
RESOLVED
FIXED
Autoridad de Certificacion Firmaprofesional
AI Summary
Firmaprofesional identified a typo in the CA/B Forum OIDs used in their SSL certificates, which affected a total of 587 certificates. The error was discovered during an internal audit on March 22, 2021, leading to an immediate halt in certificate issuance. The incorrect OIDs were corrected, and affected certificates were revoked within five days. The CA has since implemented measures to prevent similar issues in the future, including improved auditing processes.
Chronology
- Discovery of typo in CA/B Forum OIDs
- Issuance of affected certificates stopped
- Last affected certificates revoked
Participants
chemalogo@isigma.es
clopez@firmaprofesional.com
bwilson@mozilla.com
External References
Similar Local Cases
Firmaprofesional: AC Firmaprofesional - INFRAESTRUCTURA insufficient serial number entropy
Firmaprofesional: Incorrect publication of information for "Test Website - Revoked" URL in the CCADB.
Firmaprofesional: Undisclosed Intermediate certificate SDS
Firmaprofesional: Policy Qualifiers other than id-qt-cps present for certificate
Add CFEA and OTC Firmaprofesional's Subordinate CAs to OneCRL
Firmaprofesional / SIGNE: No BR Audit for intermediate CA technically capable of issuing TLS certs
Firmaprofesional: 2022 - StateorProvince field
Telia: Invalid email contact address was used for few domains