← Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) cases
Bugzilla #2012326 Certificate Misissuance

FNMT-RCM: Issuance of EV/OV certificate using previously revoked keyCompromise key

RESOLVED FIXED Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

FNMT-RCM reported an incident in which it was informed by a third party that a TLS certificate had been mis-issued using a private key that had previously been revoked with reason code "keyCompromise". The compliance team investigated and determined that the incident violated CAB Forum Baseline Requirements section 6.1.1.3 (subscriber key pair generation), which requires rejecting certificate requests when the applicant’s private key has previously been notified as key compromised. FNMT-RCM stated that it scanned certificates and found two additional affected certificates, but those were already expired; within 24 hours of becoming aware, the affected active certificate was revoked with reason "key compromised". FNMT-RCM also reported that issuance was stopped during investigation, a script to detect compromised keys was installed, and the issuance service was later reactivated. In its remediation, FNMT-RCM stated that it implemented application changes to check whether a key is compromised and configured scheduled automated scans to detect certificates issued with compromised keys. The incident report closure summary states that the action items were completed and requests closure, and the bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:15 UTC Revised: 2026-06-16 19:16 UTC Confidence: 0.86 10 comments
Chronology
  1. Certificate "B" was issued using the same CSR/key as a previously issued certificate that would later be revoked for key compromise.
  2. FNMT-RCM was informed by a third party of TLS certificate mis-issuance involving a previously revoked keyCompromise key.
  3. FNMT-RCM revoked the affected active certificate within 24 hours with reason "key compromised".
  4. FNMT-RCM submitted a report closure summary stating remediation actions were completed and requested closure.
Thread Activity
  1. Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — Opened a preliminary incident report stating FNMT became aware of a certificate issued using a previously revoked keyCompromise key and that the certificate was revoked within 24 hours, with a full incident report planned.
  2. CCADB representative — Asked whether the affected certificate was DV, OV, or another type.
  3. Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — Responded that the affected certificate was an EV certificate.
  4. Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — Submitted the full incident report describing third-party disclosure, identification of additional affected (expired) certificates, revocation within 24 hours, and remediation steps including stopping issuance and installing a compromised-key detection script.
  5. Google representative — Requested updates to the timeline and asked about FNMT’s monitoring process for the Bugzilla CA Certificate Compliance component and why related incidents did not trigger earlier review.
  6. Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — Provided clarifications on the non-compliance start date, described monitoring and planned improvements, and explained why earlier incidents did not trigger earlier automated scans.
  7. Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — Republished the incident report with updated timeline and status of action items.
  8. Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — Posted the report closure summary stating the incident description, root causes, remediation actions (revocation, application fix, scheduled automated scans), and that action items were completed and closure was requested.
  9. CCADB representative — Issued a final call for comments and noted the bug would be closed approximately 2026-02-27.
Participants
Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) CCADB representative Google representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1744722 RESOLVED Certificate Misissuance Opened 2021-12-07 · Closed 2023-02-22 · 81% similar
FNMT: Invalid localityName
#1977253 RESOLVED Certificate Misissuance Opened 2025-07-14 · Closed 2025-09-15 · 78% similar
Sectigo: OV reuse data applied for wrong organization
#1966515 RESOLVED Certificate Misissuance Opened 2025-05-14 · Closed 2025-06-04 · 75% similar
Let's Encrypt: Issuance for Invalid Internationalized Domain Name
#1947207 RESOLVED Certificate Misissuance Opened 2025-02-10 · Closed 2025-02-28 · 69% similar
FNMT: Incorrect publication of information for Test Website - Valid
#2023458 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2026-03-15 · Closed 2026-06-12 · 69% similar
D-Trust: TLS Precertificates Exceeding the Maximum Validity Period Allowed by the TLS Baseline Requirements
#2055551 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-07-16 Still Open · 68% similar
HARICA: Issuance of Server TLS Certificates with id-kp-clientAuth KeyPurposeID against CP/CPS
#2037000 ASSIGNED Self Reported Incident Certificate Misissuance Problem Reporting Failure Opened 2026-05-05 Still Open · 68% similar
D-Trust: Missing Pre-Sign Linting for S/MIME Issuing CAs
#2032468 ASSIGNED Ca Certificate Compliance Certificate Misissuance Problem Reporting Failure Audit Finding Opened 2026-04-16 Still Open · 68% similar
VISA: Misissuance detected by PKIMetal

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action