← Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) cases
Bugzilla #1875942 Ca Certificate Compliance

FNMT: Certificates issued included Policy qualifiers other than id-qt-cps

RESOLVED FIXED Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

On January 22, 2024, FNMT discovered that it had issued 712 TLS certificates since September 15, 2023, which included Policy Qualifiers other than id-qt-cps, violating BR 7.1.2.7.9. Following this discovery, FNMT suspended the issuance of these certificates and began notifying affected subscribers to revoke their certificates. The CA completed the revocation of all affected certificates within five days. A detailed incident report was provided, outlining the root cause as a failure in the profile review process and reliance on a single reviewer. FNMT has since implemented corrective actions, including a checklist for profile reviews and enhanced monitoring tools.

Model: gpt-4o-mini Generated: 2026-06-13 21:13 UTC Revised: 2026-06-16 19:15 UTC Confidence: 0.90 13 comments
Chronology
  1. FNMT discovers issuance of non-compliant TLS certificates.
  2. All affected certificates have been revoked.
  3. FNMT requests closure of the bug after successful remediation.
Thread Activity
  1. Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — FNMT realizes it has issued non-compliant certificates and suspends their issuance.
  2. Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — FNMT provides a detailed incident report and outlines the impact and timeline.
  3. Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — All affected certificates have been revoked within 5 days.
  4. Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — FNMT confirms successful implementation of remediation items and requests bug closure.
Participants
Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) Mozilla representative
External References
Similar Local Cases
#1544586 RESOLVED Ca Certificate Compliance Opened 2019-04-15 · Closed 2023-02-22 · 80% similar
FNMT: Findings in 2019 Audit Statement, including domain validation methods, CAA, etc.
#2056989 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-07-22 Still Open · 77% similar
FNMT: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy
#1736064 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-10-15 · Closed 2023-02-22 · 71% similar
Sectigo: Subject field with unvalidated information included in certificates
#1864204 RESOLVED Ca Certificate Compliance Opened 2023-11-10 · Closed 2024-05-10 · 71% similar
Buypass: TLS certificates with incorrect Subject attribute order
#1824319 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2023-03-24 · Closed 2023-07-20 · 71% similar
Actalis: pre-certificates with “certificateHold” as the revocation reason
#1680378 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-12-02 · Closed 2023-02-22 · 70% similar
NetLock: Replacement of enduser certificates after the EVGL 1.7.4 self-audit
#1716123 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-06-12 · Closed 2024-05-25 · 70% similar
e-commerce monitoring GmbH: CN domain not in SAN
#1879845 RESOLVED Ca Certificate Compliance Opened 2024-02-12 · Closed 2024-10-02 · 70% similar
Asseco DS / Certum: S/MIME certificates with error in subjectAlternativeName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action