FNMT: Incorrect publication of information for Test Website - Valid
The FNMT CA Program case concerns an incorrect publication of information for the “Test Website - Valid” entries in the CCADB. FNMT reported that the CCADB “Test Website -Valid” value for AC RAIZ FNMT-RCM SERVIDORES SEGUROS corresponded to an expired certificate. FNMT’s incident report states that the URLs https://testactivetipo1.cert.fnmt.es and https://testactivetipo2.cert.fnmt.es were protected by expired EV and OV test website certificates, which FNMT characterized as a non-compliance breach of CA/Browser Forum TLS BR 2.2 Publication of information. FNMT said it updated the non-compliant node, rebalanced the web cluster, and deployed a monitoring system to detect future issues. FNMT also revised its certificate renewal procedure to ensure certificates are updated on both nodes and committed to improving procedures and monitoring. The bug was resolved as FIXED, with FNMT requesting closure after stating the disclosed action items were completed.
- New valid test certificates were issued and valid test certificates were updated on the active web node.
- A TLS termination web cluster balanced to a passive node that was not updated, causing active certificates to become expired.
- Compliance staff reviewed the test websites and confirmed both test URLs were affected, then technical staff updated the non-compliant node and the cluster was rebalanced.
- FNMT posted a preliminary incident report on Bugzilla and deployed a monitoring system.
- FNMT submitted a report closure summary and requested closure; Mozilla indicated intent to close on 28-Feb-2025.
- Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — Posted a preliminary incident report stating FNMT diagnosed and solved the incorrect publication issue and would issue a full report with findings and corrective actions.
- Community commenter — Suggested automated monitoring (referencing another Bugzilla comment) to permanently stop this type of problem.
- Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — Agreed to implement monitoring and stated FNMT reviewed and enhanced monitoring systems for better coverage.
- Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — Provided the incident report with impact, timeline, root causes, and action items (including monitoring deployment and procedure revision).
- Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — Updated the details of affected certificates by fixing a typo in the URL of the certificates.
- Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — Submitted a report closure summary stating remediation actions were completed and requested bug closure.
- Mozilla representative — Indicated intent to close the bug on Friday, 28-Feb-2025, unless issues or questions remained.