FNMT: Certificates issued included Policy qualifiers other than id-qt-cps
On January 22, 2024, FNMT discovered that it had issued 712 TLS certificates since September 15, 2023, which included Policy Qualifiers other than id-qt-cps, violating BR 7.1.2.7.9. Following this discovery, FNMT suspended the issuance of these certificates and began notifying affected subscribers to revoke their certificates. The CA completed the revocation of all affected certificates within five days. A detailed incident report was provided, outlining the root cause as a failure in the profile review process and reliance on a single reviewer. FNMT has since implemented corrective actions, including a checklist for profile reviews and enhanced monitoring tools.
- FNMT discovers issuance of non-compliant TLS certificates.
- All affected certificates have been revoked.
- FNMT requests closure of the bug after successful remediation.
- Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — FNMT realizes it has issued non-compliant certificates and suspends their issuance.
- Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — FNMT provides a detailed incident report and outlines the impact and timeline.
- Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — All affected certificates have been revoked within 5 days.
- Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — FNMT confirms successful implementation of remediation items and requests bug closure.