← AC Camerfirma, S.A. cases
Bugzilla #723722
Self Reported Incident
EV SSL certificate (and OCSP response) for www.camerfirma.com fails to meet EV Guidelines
RESOLVED
FIXED
AC Camerfirma, S.A.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
The case involves Camerfirma, which reported that their EV SSL certificates were not being treated as EV in Firefox. The issue was identified as a failure to comply with EV guidelines, including the use of a 1024-bit key and an outdated OCSP response. Camerfirma acknowledged the problem and committed to resolving it by updating their OCSP responder and reissuing certificates with a 2048-bit key. The CA confirmed that the issues were addressed, and the EV treatment was restored for their website.
Chronology
- Camerfirma reported issues with their EV SSL certificates not being recognized correctly in Firefox.
- Camerfirma confirmed the resolution of the OCSP service issue and updated the key length to 2048 bits.
Thread Activity
- Mozilla representative — Camerfirma notified that their root certs are no longer given EV Treatment.
- AC Camerfirma, S.A. — Camerfirma committed to solving the OCSP responder and key length issues ASAP.
- Mozilla representative — Camerfirma has fixed the issue with their OCSP service and revoked non-compliant EV test certificates.
Participants
Mozilla representative
Mversen representative
Startcom representative
Velox representative
AC Camerfirma, S.A.
External References
Similar Local Cases
Camerfirma: Certs issued with same issuer and serial number
Camerfirma: Outdated audit statements for intermediate certs
Camerfirma: Govern d'Andorra audits
Camerfirma: Invalid authorityKeyIdentifier, violating Mozilla Policy and RFC 5280
Camerfirma: Failure to abide by Section 8 of Mozilla Policy: Unauthorized, improperly disclosed Subordinate CA
Camerfirma: Infocert misissued certificates
Camerfirma: Certificates without CABForum OV Reserved Policy Identifier
Camerfirma: suspicious certificate for com.com