Hi Peter

When we realize the problem there were many certificates issued by the newer
SubCA and taken into account that the older SubCA only issued a few
"internal use" certificates (6) and it has never been used since then . We
found neither security nor administrative problem in maintain this
situation. The problem appeared when we disclose this UNUSED CA in the
CCADB.

Best Regard

Ramiro Muñoz Muñoz 
AC Camerfirma SA.
CTO, Exploitation Manager, CISA.
+34 619 746 291 · [email protected]. 
https://www.linkedin.com/in/ramirom.
________________________________________
¿ Has probado c-Office ? 
firma de documentos, factura electrónica, puesta a disposición,
notificaciones fehacientes y mucho, mucho más.. https://www.c-office.es


-----Mensaje original-----
De: dev-security-policy
[mailto:dev-security-policy-bounces+ramirom=camerfirma....@lists.mozilla.org
] En nombre de Peter Gutmann via dev-security-policy
Enviado el: martes, 10 de octubre de 2017 8:37
Para: [email protected]; [email protected]
Asunto: Re: Doppelganger/tripleganger intermediate certificates

ramirommunoz--- via dev-security-policy
<[email protected]> writes:

>1) How your CA first became aware of the problem Affected certificates 
>Serial number:0d dates:15 Nov-2007 to 8-Nov-2032 Name:AC Camerfirma 
>Express corporate Server(1) Serial number:0d dates:23 Feb-2010 to
20-Feb-2022 Name:AC Camerfirma AAPP(2).
>
>We were aware some time later of Febr 2010 after issuing the (2) SubCA 
>when we already had issued valid certificates.

So just to confirm this, the CA has known about these invalid certificates
for SEVEN YEARS and is only now taking action over them?

Do the BR's contain any text on timeliness of action, or is it like the
Swiss plan to shut down their reactors?  (German plan: We've voted to shut
them down, here's the schedule.  Swiss plan: We've voted to shut them down,
and now we've finished voting on shutting them down).

Peter.
_______________________________________________
dev-security-policy mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security-policy

_______________________________________________
dev-security-policy mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security-policy

Reply via email to