← Autoridad de Certificacion Firmaprofesional cases
Bugzilla #2054448 Ca Certificate Compliance Incident Self Reported Incident Validation Issue Policy Document Issue

Firmaprofesional Chrome Root Program policy non-compliance for dedicated TLS hierarchy / EKU requirements

UNCONFIRMED Autoridad de Certificacion Firmaprofesional
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Firmaprofesional reported a Chrome Root Program incident involving its Chrome-included root certificate `Autoridad de Certificacion Firmaprofesional CIF A62634068`. Chrome notified Firmaprofesional that unexpired, unrevoked subordinate CA certificates validating to that root did not meet the Chrome Root Program Policy requirement for dedicated TLS server authentication hierarchies. Firmaprofesional’s review identified seven affected subordinate CA certificates, and Chrome later confirmed the seventh certificate as non-compliant. The company said the affected hierarchy cannot be modified to remedy the non-compliance, will not seek an exemption or replacement Chrome-trusted root for this hierarchy, and will request voluntary removal of the root from the applicable browser root programs. Chrome announced an `sctNotAfter` constraint of 2026-09-30 23:59:59 UTC, and Firmaprofesional requested a removal effective date of 2026-10-19. The latest thread update says work on the open action items remains in progress and asks for the next update date to be set to 2026-08-31.

Model: gpt-5.4-mini Generated: 2026-07-16 19:55 UTC Revised: 2026-08-02 08:01 UTC Confidence: 0.96 5 comments
Chronology
  1. Chrome Root Program dedicated TLS hierarchy requirements became applicable to existing Chrome-included roots.
  2. Chrome notified Firmaprofesional that subordinate CA certificates validating to `Autoridad de Certificacion Firmaprofesional CIF A62634068` did not meet the dedicated TLS hierarchy requirements.
  3. Firmaprofesional filed its full incident report, confirmed seven affected subordinate CA certificates, and said it will request voluntary root removal.
  4. Firmaprofesional said work on the open action items remains in progress and requested a next update date of 2026-08-31.
Thread Activity
  1. Autoridad de Certificacion Firmaprofesional — Filed a preliminary incident report describing Chrome’s notification, listing seven affected subordinate CA certificates, and stating that Firmaprofesional would proceed with Chrome’s phase-out.
  2. Autoridad de Certificacion Firmaprofesional — Corrected a drafting error in the preliminary report and said the investigation and full report preparation were still in progress, with no change to the seven-certificate scope.
  3. Autoridad de Certificacion Firmaprofesional — Posted the full incident report, confirmed the seven-certificate scope, and stated that Firmaprofesional will request voluntary removal of the affected root from the applicable browser root programs.
  4. Autoridad de Certificacion Firmaprofesional — Said work on the open action items remains in progress and requested that the Bugzilla Whiteboard next update date be set to 2026-08-31.
Participants
Autoridad de Certificacion Firmaprofesional Mozilla representative
Similar Local Cases
#2056942 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-07-22 Still Open · 79% similar
SDAIA: Missing S/MIME WebTrust audit coverage
#1398240 RESOLVED Ca Certificate Compliance Incident Opened 2017-09-08 · Closed 2023-02-22 · 79% similar
Firmaprofesional: Non-BR-Compliant OCSP Responders
#1717795 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Opened 2021-06-23 · Closed 2023-02-22 · 79% similar
Firmaprofesional: 2021 Audit Report Finding 3 out of 3
#1368171 RESOLVED Ca Certificate Compliance Incident Opened 2017-05-26 · Closed 2024-06-30 · 78% similar
Firmaprofesional: Non-audited, non-technically-constrained intermediate certificates
#1538638 RESOLVED Ca Certificate Compliance Self Reported Incident Revocation Issue Opened 2019-03-25 · Closed 2023-02-22 · 78% similar
Firmaprofesional: AC Firmaprofesional - INFRAESTRUCTURA insufficient serial number entropy
#1717791 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Opened 2021-06-23 · Closed 2023-02-22 · 77% similar
Firmaprofesional: 2021 Audit Report Finding 2 out of 3
#1769240 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2022-05-13 · Closed 2023-02-22 · 77% similar
Firmaprofesional: 2022 - SSL certificates issued with wrong Organization ID number
#1771715 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2022-05-30 · Closed 2023-02-22 · 77% similar
Firmaprofesional: 2022 - StateorProvince field

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action