FNMT: two non-TLS intermediate CAs lacked EKU; OneCRL mitigation requested while migration continues
FNMT reported that two intermediate CA certificates issued on 2019-11-28 under the AC RAIZ FNMT-RCM hierarchy lacked the Extended Key Usage extension required by Mozilla Root Store Policy. The affected intermediates are AC Unidades de Sellado de Tiempo and AC Sector Publico. FNMT said these subordinate CAs are used for non-TLS trust services and have not been used for publicly trusted TLS issuance. FNMT stated that migration to dedicated single-purpose hierarchies is underway, and that it requested OneCRL inclusion of the affected intermediates as an interim mitigation. FNMT also said the certificates have not been revoked yet, and that revocation will occur once there are no remaining valid certificates issued under them. FNMT later clarified that this bug documents one part of a broader transition plan and that CPS wording about subject DN uniqueness will be revised in a future update. The most recent update said there were no new developments and that the OneCRL request remains included for evaluation.
- FNMT issued two intermediate CA certificates without the required EKU extension.
- FNMT learned of the non-compliant intermediates after an email about a Mozilla dev-security-policy post.
- FNMT opened a preliminary incident report for the missing-EKU intermediates.
- FNMT filed the full incident report and said migration and OneCRL mitigation were in progress.
- FNMT requested OneCRL inclusion for the two affected intermediate CA certificates and confirmed they had not been revoked.
- Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — FNMT reported the incident, named the two affected intermediate CA certificates, and said migration to dedicated hierarchies had already begun.
- Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — FNMT said the full incident report was still being prepared and would be published by 2026-08-03.
- Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — FNMT published the full incident report, described the migration plan, and said it would request OneCRL inclusion as an interim mitigation.
- Community commenter — A commenter quoted the report and challenged the planned revocation timeline against the Baseline Requirements for subordinate CA revocation.
- Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — FNMT said the incident concerns remediation of the two non-TLS subordinate CAs and that TLS trust-bit removal is being tracked separately in Bug 2031303.
- Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — FNMT clarified that this bug documents one part of its broader transition plan and said it will revise CPS wording in a future revision.
- Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — FNMT requested inclusion of the two intermediate CA certificates in OneCRL as an interim mitigation and confirmed the certificates have not been revoked.
- Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — FNMT said there were no new updates to report.
- Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — FNMT said there were no new developments and that the OneCRL request remains included in the incident for evaluation.