← Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) cases
Bugzilla #1947207 Certificate Misissuance

FNMT: Incorrect publication of information for Test Website - Valid

RESOLVED FIXED Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The FNMT CA Program case concerns an incorrect publication of information for the “Test Website - Valid” entries in the CCADB. FNMT reported that the CCADB “Test Website -Valid” value for AC RAIZ FNMT-RCM SERVIDORES SEGUROS corresponded to an expired certificate. FNMT’s incident report states that the URLs https://testactivetipo1.cert.fnmt.es and https://testactivetipo2.cert.fnmt.es were protected by expired EV and OV test website certificates, which FNMT characterized as a non-compliance breach of CA/Browser Forum TLS BR 2.2 Publication of information. FNMT said it updated the non-compliant node, rebalanced the web cluster, and deployed a monitoring system to detect future issues. FNMT also revised its certificate renewal procedure to ensure certificates are updated on both nodes and committed to improving procedures and monitoring. The bug was resolved as FIXED, with FNMT requesting closure after stating the disclosed action items were completed.

Model: gpt-5.4-nano Generated: 2026-06-13 21:14 UTC Revised: 2026-06-16 19:15 UTC Confidence: 0.90 7 comments
Chronology
  1. New valid test certificates were issued and valid test certificates were updated on the active web node.
  2. A TLS termination web cluster balanced to a passive node that was not updated, causing active certificates to become expired.
  3. Compliance staff reviewed the test websites and confirmed both test URLs were affected, then technical staff updated the non-compliant node and the cluster was rebalanced.
  4. FNMT posted a preliminary incident report on Bugzilla and deployed a monitoring system.
  5. FNMT submitted a report closure summary and requested closure; Mozilla indicated intent to close on 28-Feb-2025.
Thread Activity
  1. Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — Posted a preliminary incident report stating FNMT diagnosed and solved the incorrect publication issue and would issue a full report with findings and corrective actions.
  2. Community commenter — Suggested automated monitoring (referencing another Bugzilla comment) to permanently stop this type of problem.
  3. Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — Agreed to implement monitoring and stated FNMT reviewed and enhanced monitoring systems for better coverage.
  4. Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — Provided the incident report with impact, timeline, root causes, and action items (including monitoring deployment and procedure revision).
  5. Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — Updated the details of affected certificates by fixing a typo in the URL of the certificates.
  6. Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — Submitted a report closure summary stating remediation actions were completed and requested bug closure.
  7. Mozilla representative — Indicated intent to close the bug on Friday, 28-Feb-2025, unless issues or questions remained.
Participants
Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) Community commenter Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1696872 RESOLVED Certificate Misissuance Opened 2021-03-08 · Closed 2025-03-20 · 88% similar
FNMT: Missisuance of web site certificates without CA/Browser Forum’s reserved policy OID
#1922906 RESOLVED Certificate Misissuance Opened 2024-10-05 · Closed 2025-02-12 · 85% similar
FNMT: LDAP URI in CRL Distribution Points Extension
#2056989 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-07-22 Still Open · 75% similar
FNMT: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy
#1910322 RESOLVED Certificate Misissuance Revocation Issue Opened 2024-07-29 · Closed 2025-06-18 · 74% similar
DigiCert: Random value in CNAME without underscore prefix
#1939809 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-01-03 · Closed 2026-06-12 · 70% similar
D-Trust: QCStatement with http link of PKI Disclosure Statements
#1954861 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-03-18 · Closed 2025-04-09 · 69% similar
Let's Encrypt: Early CRL Removal Incident
#1936908 RESOLVED Certificate Misissuance Opened 2024-12-12 · Closed 2025-03-18 · 69% similar
DigiCert: Encoded HTML entities in attribute values
#1945867 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-02-04 · Closed 2025-04-18 · 69% similar
Izenpe: Incorrect Unicode characters in Subject

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action