FNMT incident report: post-2019 subordinate CA certificates missing required EKU extension
FNMT opened this bug as a preliminary incident report after being notified of a Mozilla dev-security-policy post that identified two subordinate CA certificates issued after 2019-01-01 without the required EKU extension. The affected certificates were AC Unidades de Sellado de Tiempo and AC Sector Publico, both issued on 2019-11-28. FNMT stated that these subordinate certificates are not used to issue public-trust TLS certificates. It also said it had already initiated migration to dedicated single-purpose hierarchies for subordinate CAs under the AC RAIZ NMT-RCM hierarchy that do not issue TLS server certificates. The report cites Mozilla Root Store Policy section 5.3 on intermediate certificates as the relevant policy. The bug remains assigned, with FNMT providing the incident disclosure and describing the migration work already underway.
- FNMT issued two subordinate CA certificates without the required EKU extension.
- FNMT was notified of a Mozilla dev-security-policy post identifying the two subordinate certificates.
- FNMT filed a preliminary incident report and said it had begun migrating non-TLS subordinate CAs to dedicated hierarchies.
- Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — FNMT reported the incident, identified the two affected subordinate CA certificates, cited the applicable Mozilla policy, and said migration to dedicated hierarchies was already underway.