← Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) cases
Bugzilla #1875942
Certificate Problem Report
FNMT: Certificates issued included Policy qualifiers other than id-qt-cps
RESOLVED
FIXED
Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT)
AI Summary
On January 22, 2024, FNMT identified that it had issued 712 TLS certificates since September 15, 2023, which included Policy Qualifiers other than the required id-qt-cps, violating BR 7.1.2.7.9. The affected certificates were suspended, and a notification process was initiated for subscribers. All affected certificates were revoked within five days. The root cause was a failure in the compliance review process, exacerbated by reliance on a single reviewer and outdated tools. FNMT has since implemented corrective actions, including a checklist for reviews and improved monitoring tools.
Chronology
- FNMT detects non-compliance issue regarding issued certificates.
- FNMT submits incident report detailing affected certificates.
- All affected certificates revoked.
- FNMT updates on action items and implementation of compliance measures.
- FNMT confirms successful remediation and requests closure of the bug.
Participants
Amaya Espinosa
Ben Wilson
External References
Similar Local Cases
FNMT: CRL problems displayed during the monitoring
FNMT: Delayed response to CPR sender related bug 2012326
FNMT: CP/CPS, Revocation Requests Mechanism, Certificate Problem Report, CRL and OCSP disruption
Digicert: SMIME certificate with unvalidated information
KIR S.A.: DV certificates with locality name, organization name and stateOrProvinceName
iTrusChina: CRL Reason Codes
FNMT: Issuance of QCP-n certificates without verifying identity
NETLOCK: SSL certificates with OU field