> > Issuer: https://crt.sh/?caid=140 > Issuer O: AC Camerfirma SA CIF A82743287 > Issuer CN: Chambers of Commerce Root > Subject CN: (id=1252) AC CAMERFIRMA AAPP > (id=12625404) AC Camerfirma Express Corporate Server > Serial #: 0d > Certs: https://crt.sh/?id=1252 > https://crt.sh/?id=12625404 > Revoked?: No
Hi Rob Here the incident report from Camerfirma: 1) How your CA first became aware of the problem Affected certificates Serial number:0d dates:15 Nov-2007 to 8-Nov-2032 Name:AC Camerfirma Express corporate Server(1) Serial number:0d dates:23 Feb-2010 to 20-Feb-2022 Name:AC Camerfirma AAPP(2). We were aware some time later of Febr 2010 after issuing the (2) SubCA when we already had issued valid certificates. 2) A timeline of the actions your CA took in response. The SubCA (1) was an internal CA to issue only 6 test certificates. This SubCA is not used anymore since 08-11-2014. Certificates issued by SubCA (1) /C=ES/ST=Madrid/L=Madrid/O=AC Camerfirma/OU=Tecnico/CN=127.0.0.1/[email protected]/serialNumber=A99999999 /C=ES/ST=Madrid/L=Madrid/O=AC Camerfirma SA/OU=Sistemas/CN=*.camerfirma.com/[email protected]/serialNumber=A82743287 /C=ES/ST=Avila/L=Avila/O=AC Camerfirma SA/OU=Sistemas/CN=*.camerfirma.com/[email protected]/serialNumber=A82743287 /C=ES/ST=Madrid/L=Madrid/O=AC Camerfirma/OU=Tecnico/CN=test_valido/[email protected]/serialNumber=A99999999 /C=ES/ST=Madrid/L=Madrid/O=AC Camerfirma/OU=Tecnico/CN=test_revocado/[email protected]/serialNumber=A99999999 /C=ES/ST=Madrid/L=Madrid/O=AC Camerfirma/OU=Tecnico/CN=test_caducado/[email protected]/serialNumber=A99999999 3) Whether your CA has stopped, or has not yet stopped, issuing TLS/SSL The SubCA (1) issue no certificates since since 08-11-2014. 4) A summary of the problematic certificates. For each problem: number of certs, and the date the first and last certs with that problem were issued. See answer 1. 5) The complete certificate data for the problematic certificates. See answer 1. 6) Explanation about how and why the mistakes were made or bugs introduced, and how they avoided detection until now. The generation of SubCA certificates is done manually, in the protected physical environment of our Root CA off-line, with the prior authorization of our management and in the presence of our internal auditor. We used a wrong template in the creation SubCA process. We reviewed the templates and classified them to avoid new problems. This control has been effective since no other similar problem has arisen so far. 7) List of steps your CA is taking to resolve the situation and ensure such issuance will not be repeated in the future, accompanied with a timeline of when your CA expects to accomplish these things. Templates are now approved by the tech management and review by our internal auditor before going into production. Regards Ramiro _______________________________________________ dev-security-policy mailing list [email protected] https://lists.mozilla.org/listinfo/dev-security-policy

