← Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) cases
Bugzilla #2056989 Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Policy Document Issue

FNMT incident report: post-2019 subordinate CA certificates missing required EKU extension

ASSIGNED Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

FNMT opened this bug as a preliminary incident report after being notified of a Mozilla dev-security-policy post that identified two subordinate CA certificates issued after 2019-01-01 without the required EKU extension. The affected certificates were AC Unidades de Sellado de Tiempo and AC Sector Publico, both issued on 2019-11-28. FNMT stated that these subordinate certificates are not used to issue public-trust TLS certificates. It also said it had already initiated migration to dedicated single-purpose hierarchies for subordinate CAs under the AC RAIZ NMT-RCM hierarchy that do not issue TLS server certificates. The report cites Mozilla Root Store Policy section 5.3 on intermediate certificates as the relevant policy. The bug remains assigned, with FNMT providing the incident disclosure and describing the migration work already underway.

Model: gpt-5.4-mini Generated: 2026-07-26 06:24 UTC Confidence: 0.96 1 comment
Chronology
  1. FNMT issued two subordinate CA certificates without the required EKU extension.
  2. FNMT was notified of a Mozilla dev-security-policy post identifying the two subordinate certificates.
  3. FNMT filed a preliminary incident report and said it had begun migrating non-TLS subordinate CAs to dedicated hierarchies.
Thread Activity
  1. Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — FNMT reported the incident, identified the two affected subordinate CA certificates, cited the applicable Mozilla policy, and said migration to dedicated hierarchies was already underway.
Participants
Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT)
Similar Local Cases
#1596949 RESOLVED Ca Documents Policy Document Issue Self Reported Incident Opened 2019-11-15 · Closed 2023-02-22 · 79% similar
FNMT: CP/CPS lack CAA processing details
#1875942 RESOLVED Ca Certificate Compliance Opened 2024-01-22 · Closed 2024-08-28 · 77% similar
FNMT: Certificates issued included Policy qualifiers other than id-qt-cps
#1922906 RESOLVED Certificate Misissuance Opened 2024-10-05 · Closed 2025-02-12 · 76% similar
FNMT: LDAP URI in CRL Distribution Points Extension
#1947207 RESOLVED Certificate Misissuance Opened 2025-02-10 · Closed 2025-02-28 · 75% similar
FNMT: Incorrect publication of information for Test Website - Valid
#1963778 RESOLVED Incident Revocation Issue Opened 2025-05-01 · Closed 2025-11-20 · 74% similar
FNMT: CP/CPS, Revocation Requests Mechanism, Certificate Problem Report, CRL and OCSP disruption
#2026351 RESOLVED Self Reported Incident Certificate Misissuance Opened 2026-03-25 · Closed 2026-05-18 · 73% similar
Identrust: Root CrossSign, of dedicated Roots, missing EKU
#2038351 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-05-08 Still Open · 71% similar
Let's Encrypt: Gen Y Cross-Certified Subordinate CAs missing serverAuth EKU
#1586795 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-10-07 · Closed 2023-02-22 · 71% similar
NetLock: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action