> 
>      Issuer: https://crt.sh/?caid=140
>    Issuer O: AC Camerfirma SA CIF A82743287
>   Issuer CN: Chambers of Commerce Root
> Subject CN: (id=1252) AC CAMERFIRMA AAPP
>              (id=12625404) AC Camerfirma Express Corporate Server
>    Serial #: 0d
>       Certs: https://crt.sh/?id=1252
>              https://crt.sh/?id=12625404
>    Revoked?: No

Hi Rob
Here the incident report from Camerfirma:

1) How your CA first became aware of the problem
Affected certificates
Serial number:0d dates:15 Nov-2007 to 8-Nov-2032 Name:AC Camerfirma Express 
corporate Server(1)
Serial number:0d dates:23 Feb-2010 to 20-Feb-2022 Name:AC Camerfirma AAPP(2).

We were aware some time later of Febr 2010 after issuing the (2) SubCA when we 
already had issued valid certificates.

2) A timeline of the actions your CA took in response.
The SubCA (1) was an internal CA to issue only 6 test certificates. This SubCA 
is not used anymore since 08-11-2014.

Certificates issued by SubCA (1)
/C=ES/ST=Madrid/L=Madrid/O=AC 
Camerfirma/OU=Tecnico/CN=127.0.0.1/[email protected]/serialNumber=A99999999
/C=ES/ST=Madrid/L=Madrid/O=AC Camerfirma 
SA/OU=Sistemas/CN=*.camerfirma.com/[email protected]/serialNumber=A82743287
/C=ES/ST=Avila/L=Avila/O=AC Camerfirma 
SA/OU=Sistemas/CN=*.camerfirma.com/[email protected]/serialNumber=A82743287
/C=ES/ST=Madrid/L=Madrid/O=AC 
Camerfirma/OU=Tecnico/CN=test_valido/[email protected]/serialNumber=A99999999
/C=ES/ST=Madrid/L=Madrid/O=AC 
Camerfirma/OU=Tecnico/CN=test_revocado/[email protected]/serialNumber=A99999999
/C=ES/ST=Madrid/L=Madrid/O=AC 
Camerfirma/OU=Tecnico/CN=test_caducado/[email protected]/serialNumber=A99999999


3) Whether your CA has stopped, or has not yet stopped, issuing TLS/SSL
The SubCA (1) issue no certificates since since 08-11-2014.


4) A summary of the problematic certificates. For each problem: number
of certs, and the date the first and last certs with that problem were
issued.
See answer 1.


5) The complete certificate data for the problematic certificates.
See answer 1.


6) Explanation about how and why the mistakes were made or bugs
introduced, and how they avoided detection until now.

The generation of SubCA certificates is done
manually, in the protected physical environment of our Root CA off-line, 
with the prior authorization of our management and in the presence of our 
internal auditor.

We used a wrong template in the creation SubCA process. 
We reviewed the templates and classified them to avoid new problems.
This control has been effective since no other similar problem has arisen so 
far. 

7) List of steps your CA is taking to resolve the situation and ensure
such issuance will not be repeated in the future, accompanied with a
timeline of when your CA expects to accomplish these things.

Templates are now approved by the tech management and review by our internal 
auditor before going into production.

Regards
Ramiro



_______________________________________________
dev-security-policy mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security-policy

Reply via email to