FNMT-RCM: Issuance of EV/OV certificate using previously revoked keyCompromise key
FNMT-RCM reported an incident in which it was informed by a third party that a TLS certificate had been mis-issued using a private key that had previously been revoked with reason code "keyCompromise". The compliance team investigated and determined that the incident violated CAB Forum Baseline Requirements section 6.1.1.3 (subscriber key pair generation), which requires rejecting certificate requests when the applicant’s private key has previously been notified as key compromised. FNMT-RCM stated that it scanned certificates and found two additional affected certificates, but those were already expired; within 24 hours of becoming aware, the affected active certificate was revoked with reason "key compromised". FNMT-RCM also reported that issuance was stopped during investigation, a script to detect compromised keys was installed, and the issuance service was later reactivated. In its remediation, FNMT-RCM stated that it implemented application changes to check whether a key is compromised and configured scheduled automated scans to detect certificates issued with compromised keys. The incident report closure summary states that the action items were completed and requests closure, and the bug is marked RESOLVED with resolution FIXED.
- Certificate "B" was issued using the same CSR/key as a previously issued certificate that would later be revoked for key compromise.
- FNMT-RCM was informed by a third party of TLS certificate mis-issuance involving a previously revoked keyCompromise key.
- FNMT-RCM revoked the affected active certificate within 24 hours with reason "key compromised".
- FNMT-RCM submitted a report closure summary stating remediation actions were completed and requested closure.
- Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — Opened a preliminary incident report stating FNMT became aware of a certificate issued using a previously revoked keyCompromise key and that the certificate was revoked within 24 hours, with a full incident report planned.
- CCADB representative — Asked whether the affected certificate was DV, OV, or another type.
- Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — Responded that the affected certificate was an EV certificate.
- Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — Submitted the full incident report describing third-party disclosure, identification of additional affected (expired) certificates, revocation within 24 hours, and remediation steps including stopping issuance and installing a compromised-key detection script.
- Google representative — Requested updates to the timeline and asked about FNMT’s monitoring process for the Bugzilla CA Certificate Compliance component and why related incidents did not trigger earlier review.
- Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — Provided clarifications on the non-compliance start date, described monitoring and planned improvements, and explained why earlier incidents did not trigger earlier automated scans.
- Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — Republished the incident report with updated timeline and status of action items.
- Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — Posted the report closure summary stating the incident description, root causes, remediation actions (revocation, application fix, scheduled automated scans), and that action items were completed and closure was requested.
- CCADB representative — Issued a final call for comments and noted the bug would be closed approximately 2026-02-27.