Hi Peter When we realize the problem there were many certificates issued by the newer SubCA and taken into account that the older SubCA only issued a few "internal use" certificates (6) and it has never been used since then . We found neither security nor administrative problem in maintain this situation. The problem appeared when we disclose this UNUSED CA in the CCADB.
Best Regard Ramiro Muñoz Muñoz AC Camerfirma SA. CTO, Exploitation Manager, CISA. +34 619 746 291 · [email protected]. https://www.linkedin.com/in/ramirom. ________________________________________ ¿ Has probado c-Office ? firma de documentos, factura electrónica, puesta a disposición, notificaciones fehacientes y mucho, mucho más.. https://www.c-office.es -----Mensaje original----- De: dev-security-policy [mailto:dev-security-policy-bounces+ramirom=camerfirma....@lists.mozilla.org ] En nombre de Peter Gutmann via dev-security-policy Enviado el: martes, 10 de octubre de 2017 8:37 Para: [email protected]; [email protected] Asunto: Re: Doppelganger/tripleganger intermediate certificates ramirommunoz--- via dev-security-policy <[email protected]> writes: >1) How your CA first became aware of the problem Affected certificates >Serial number:0d dates:15 Nov-2007 to 8-Nov-2032 Name:AC Camerfirma >Express corporate Server(1) Serial number:0d dates:23 Feb-2010 to 20-Feb-2022 Name:AC Camerfirma AAPP(2). > >We were aware some time later of Febr 2010 after issuing the (2) SubCA >when we already had issued valid certificates. So just to confirm this, the CA has known about these invalid certificates for SEVEN YEARS and is only now taking action over them? Do the BR's contain any text on timeliness of action, or is it like the Swiss plan to shut down their reactors? (German plan: We've voted to shut them down, here's the schedule. Swiss plan: We've voted to shut them down, and now we've finished voting on shutting them down). Peter. _______________________________________________ dev-security-policy mailing list [email protected] https://lists.mozilla.org/listinfo/dev-security-policy _______________________________________________ dev-security-policy mailing list [email protected] https://lists.mozilla.org/listinfo/dev-security-policy

