← Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) cases
Bugzilla #2012326
Certificate Misissuance
FNMT: Issuance of certificate using keys previously reported as compromised
RESOLVED
FIXED
Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT)
AI Summary
On January 23, 2026, FNMT-RCM was informed of a TLS certificate mis-issuance due to the use of a previously revoked private key that had suffered a key compromise. An investigation revealed that three certificates were affected, with one still active at the time of the incident. The affected certificate was revoked within 24 hours, and FNMT has committed to improving its monitoring processes to prevent future occurrences. The incident was reported by a third party, highlighting the need for enhanced verification and automated checks.
Chronology
- Incident reported by third party
- Preliminary Incident Report opened
- Full Incident Report submitted
- Report closure summary provided
Participants
Amaya Espinosa
External References
Similar Local Cases
FNMT: LDAP URI in CRL Distribution Points Extension
FNMT: OU exceeds 64 characters
FNMT: Missisuance of web site certificates without CA/Browser Forum’s reserved policy OID
Actalis: Issuance of certificate using keys previously reported as compromised
Sectigo: Incorrect EV businessCategory
DigiCert: Internal Domain Name cert mis-issuance
DigiCert: Domain validation skipped
SECOM: Failure to disclose Unconstrained Intermediate within 7 Days