← Government of Spain, Autoritat de Certificació de la Comunitat Valenciana (ACCV) cases
Bugzilla #1884532 Certificate Misissuance

ACCV: Certificates issued with cRLIssuer in CDP extension

RESOLVED FIXED Government of Spain, Autoritat de Certificació de la Comunitat Valenciana (ACCV)
AI Summary

The Government of Spain's ACCV issued over 837 certificates containing the cRLIssuer field in the CRL Distribution Points extension, which violates the Baseline Requirements. The issue was identified on March 9, 2024, following a routine review, leading to an urgent meeting and confirmation of misissuance. All affected certificates were revoked by March 14, 2024. The root cause was attributed to manual verification processes and a lack of a comprehensive matrix for certificate profile fields. ACCV has since implemented corrective actions, including improved protocols and additional linting tools to prevent future occurrences.

Model: gpt-4o-mini Generated: 2026-06-13 21:10 UTC Confidence: 0.90
Chronology
  1. Baseline Requirements for TLS 2.0.0 became effective.
  2. Misissuance confirmed; urgent meeting held.
  3. All affected certificates revoked.
  4. New protocols for incident response implemented.
  5. Pkilint added as a pre-linting tool.
Participants
Jose Amador Ryan Dickson B. Wilson
Similar Local Cases
#1536213 RESOLVED Certificate Misissuance Opened 2019-03-18 · Closed 2023-02-22 · 61% similar
ACCV: Insufficient serial number entropy
#1889570 RESOLVED Certificate Misissuance Opened 2024-04-04 · Closed 2024-08-28 · 56% similar
NETLOCK: Policy Qualifiers other than id-qt-cps is included in TLS certificates
#1908130 RESOLVED Certificate Misissuance Opened 2024-07-16 · Closed 2024-08-28 · 53% similar
NAVER Cloud Trust Services: Incorrect keyUsage for ECC certificate
#1676352 RESOLVED Certificate Misissuance Opened 2020-11-10 · Closed 2023-02-22 · 52% similar
Microsec: Certificate validity period greater than 398 days
#1782391 RESOLVED Certificate Misissuance Opened 2022-07-31 · Closed 2023-02-22 · 51% similar
GlobalSign: EV certificate with wildcard domain in common name and SAN
#1883416 RESOLVED Certificate Misissuance Opened 2024-03-04 · Closed 2024-08-28 · 51% similar
Certigna: TLS certificates with Basic constraint non-critical
#1883731 RESOLVED Certificate Misissuance Opened 2024-03-05 · Closed 2024-06-28 · 50% similar
Actalis: Certificates issued with invalid RDN order
#1745015 RESOLVED Certificate Misissuance Opened 2021-12-08 · Closed 2023-02-22 · 50% similar
eMudhra: emSign CA Invalid OrganizationalUnitName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action