Firmaprofesional Chrome Root Program policy non-compliance for dedicated TLS hierarchy / EKU requirements
Firmaprofesional reported a Chrome Root Program incident involving its Chrome-included root certificate `Autoridad de Certificacion Firmaprofesional CIF A62634068`. Chrome notified Firmaprofesional that unexpired, unrevoked subordinate CA certificates validating to that root did not meet the Chrome Root Program Policy requirement for dedicated TLS server authentication hierarchies. Firmaprofesional’s review identified seven affected subordinate CA certificates, and Chrome later confirmed the seventh certificate as non-compliant. The company said the affected hierarchy cannot be modified to remedy the non-compliance, will not seek an exemption or replacement Chrome-trusted root for this hierarchy, and will request voluntary removal of the root from the applicable browser root programs. Chrome announced an `sctNotAfter` constraint of 2026-09-30 23:59:59 UTC, and Firmaprofesional requested a removal effective date of 2026-10-19. The latest thread update says work on the open action items remains in progress and asks for the next update date to be set to 2026-08-31.
- Chrome Root Program dedicated TLS hierarchy requirements became applicable to existing Chrome-included roots.
- Chrome notified Firmaprofesional that subordinate CA certificates validating to `Autoridad de Certificacion Firmaprofesional CIF A62634068` did not meet the dedicated TLS hierarchy requirements.
- Firmaprofesional filed its full incident report, confirmed seven affected subordinate CA certificates, and said it will request voluntary root removal.
- Firmaprofesional said work on the open action items remains in progress and requested a next update date of 2026-08-31.
- Autoridad de Certificacion Firmaprofesional — Filed a preliminary incident report describing Chrome’s notification, listing seven affected subordinate CA certificates, and stating that Firmaprofesional would proceed with Chrome’s phase-out.
- Autoridad de Certificacion Firmaprofesional — Corrected a drafting error in the preliminary report and said the investigation and full report preparation were still in progress, with no change to the seven-certificate scope.
- Autoridad de Certificacion Firmaprofesional — Posted the full incident report, confirmed the seven-certificate scope, and stated that Firmaprofesional will request voluntary removal of the affected root from the applicable browser root programs.
- Autoridad de Certificacion Firmaprofesional — Said work on the open action items remains in progress and requested that the Bugzilla Whiteboard next update date be set to 2026-08-31.