← Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) cases
Bugzilla #2056989 Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Repository Issue

FNMT: two non-TLS intermediate CAs lacked EKU; OneCRL mitigation requested while migration continues

ASSIGNED Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

FNMT reported that two intermediate CA certificates issued on 2019-11-28 under the AC RAIZ FNMT-RCM hierarchy lacked the Extended Key Usage extension required by Mozilla Root Store Policy. The affected intermediates are AC Unidades de Sellado de Tiempo and AC Sector Publico. FNMT said these subordinate CAs are used for non-TLS trust services and have not been used for publicly trusted TLS issuance. FNMT stated that migration to dedicated single-purpose hierarchies is underway, and that it requested OneCRL inclusion of the affected intermediates as an interim mitigation. FNMT also said the certificates have not been revoked yet, and that revocation will occur once there are no remaining valid certificates issued under them. FNMT later clarified that this bug documents one part of a broader transition plan and that CPS wording about subject DN uniqueness will be revised in a future update. The most recent update said there were no new developments and that the OneCRL request remains included for evaluation.

Model: gpt-5.4-mini Generated: 2026-07-26 06:24 UTC Revised: 2026-08-30 06:02 UTC Confidence: 0.95 11 comments
Chronology
  1. FNMT issued two intermediate CA certificates without the required EKU extension.
  2. FNMT learned of the non-compliant intermediates after an email about a Mozilla dev-security-policy post.
  3. FNMT opened a preliminary incident report for the missing-EKU intermediates.
  4. FNMT filed the full incident report and said migration and OneCRL mitigation were in progress.
  5. FNMT requested OneCRL inclusion for the two affected intermediate CA certificates and confirmed they had not been revoked.
Thread Activity
  1. Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — FNMT reported the incident, named the two affected intermediate CA certificates, and said migration to dedicated hierarchies had already begun.
  2. Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — FNMT said the full incident report was still being prepared and would be published by 2026-08-03.
  3. Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — FNMT published the full incident report, described the migration plan, and said it would request OneCRL inclusion as an interim mitigation.
  4. Community commenter — A commenter quoted the report and challenged the planned revocation timeline against the Baseline Requirements for subordinate CA revocation.
  5. Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — FNMT said the incident concerns remediation of the two non-TLS subordinate CAs and that TLS trust-bit removal is being tracked separately in Bug 2031303.
  6. Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — FNMT clarified that this bug documents one part of its broader transition plan and said it will revise CPS wording in a future revision.
  7. Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — FNMT requested inclusion of the two intermediate CA certificates in OneCRL as an interim mitigation and confirmed the certificates have not been revoked.
  8. Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — FNMT said there were no new updates to report.
  9. Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — FNMT said there were no new developments and that the OneCRL request remains included in the incident for evaluation.
Participants
Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) Community commenter
Related Bugzilla IDs Mentioned
Similar Local Cases
#2055551 ASSIGNED Certificate Misissuance Self Reported Incident Externally Reported Incident Policy Document Issue Opened 2026-07-16 Still Open · 78% similar
HARICA: Issuance of Server TLS Certificates with id-kp-clientAuth KeyPurposeID against CP/CPS
#2032473 RESOLVED Ca Certificate Compliance Incident Externally Reported Incident Certificate Misissuance Opened 2026-04-16 · Closed 2026-08-08 · 77% similar
CCA India: Misissuance detected by PKIMetal
#1890898 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2024-04-11 · Closed 2024-07-28 · 76% similar
Entrust: Failure to revoke OV TLS - CPS typographical (text placement) error
#2012326 RESOLVED Certificate Misissuance Opened 2026-01-25 · Closed 2026-02-27 · 75% similar
FNMT: Issuance of certificate using keys previously reported as compromised
#2056087 ASSIGNED Ca Certificate Compliance Incident Certificate Misissuance Delayed Revocation Opened 2026-07-19 Still Open · 70% similar
Disig: CP/CPS misstatement regarding Key Usage criticality for TLS certificates
#1579284 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-09-05 · Closed 2023-02-22 · 70% similar
TrustCor: Non-audited intermediate certificates
#1436173 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2018-02-06 · Closed 2023-02-22 · 70% similar
DigiCert: SCEE / Justica: Non-BR-Compliant Certificate Issuance
#1743935 RESOLVED Certificate Misissuance Incident Opened 2021-12-02 · Closed 2023-02-22 · 70% similar
Amazon Trust Services: Misissuance of Subordinate Per CPS

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action