← Actalis cases
Bugzilla #1034835 Ca Certificate Compliance Certificate Misissuance

Actalis: Issuing 1024-bit certificates due to delayed CSR processing

RESOLVED WORKSFORME Actalis
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The bug reports that Actalis issued a certificate containing a 1024-bit key. The reporter observed a certificate chain including “CN = Actalis Authentication CA G2” and noted the presence of 1024-bit certificates. Actalis stated the certificate was issued by mistake due to an abnormal delay between certificate request and certificate issuance: the CSR was sent to their CA system in 2013 when 1024-bit keys were still allowed, and it was kept on stand-by until checks were completed. Actalis explained that they later introduced checks to block 1024-bit keys in 2014, but by then the CSR had already been ingested. Actalis revoked the identified certificate and then investigated whether similar cases occurred, stating that additional erroneous certificates were found and would be revoked. The thread concludes with Actalis confirming that all offending certificates had been revoked, and the reporter asking whether the bug could be closed as fixed. The bug is marked RESOLVED with resolution WORKSFORME.

Model: gpt-5.4-nano Generated: 2026-06-13 13:57 UTC Revised: 2026-06-16 18:01 UTC Confidence: 0.90 8 comments
Chronology
  1. A 1024-bit-key certificate was issued by Actalis due to delayed CSR processing.
  2. Actalis revoked the mistakenly issued 1024-bit certificate and began investigating similar cases.
  3. Actalis completed revocation of all offending certificates.
Thread Activity
  1. Roeckx representative — Reported seeing recent 1024-bit certificates from the cited certificate chain and identified the Actalis Authentication CA G2 subject.
  2. Staff representative — Explained the 1024-bit certificate was issued by mistake due to abnormal delay between CSR ingestion (2013) and issuance, and stated the certificate was revoked while they investigated similar situations.
  3. Tu-ilmenau representative — Asked Kurt to verify that the reported certificate was indeed revoked.
  4. Roeckx representative — Provided that the most recent one he found was revoked end of July and listed seven other still-valid certificates that should not have been valid after 1 January 2014.
  5. Staff representative — Said they were looking into the issue and would revoke the offending certificates as soon as possible.
  6. Staff representative — Reported they were progressively revoking the erroneous certificates and would post an update when done.
  7. Staff representative — Confirmed that all the offending certificates had been revoked.
  8. Mozilla representative — Asked whether the bug should be closed as fixed.
Participants
Roeckx representative Staff representative Tu-ilmenau representative Mozilla representative
External References
Similar Local Cases
#1826713 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2023-04-06 · Closed 2023-07-20 · 99% similar
Actalis: Certificates issued with validity period greater than 398 days
#1075952 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2014-10-01 · Closed 2022-11-14 · 91% similar
D-Trust: issuing 1024 bit certificates
#1339339 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-02-14 · Closed 2023-02-22 · 79% similar
DigiCert: Non-BR Compliant Certificates - missing CP/CPS OID
#1319609 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2016-11-23 · Closed 2023-02-22 · 78% similar
Let's Encrypt: certs issued contrary to CPS due to incomplete blocklist
#988633 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2014-03-26 · Closed 2023-02-22 · 78% similar
GoDaddy: improperly encoded certificate issued by Go Daddy Secure Certification Authority
#1313873 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2016-10-29 · Closed 2022-11-14 · 78% similar
SHA-1 issuance by DocuSign root
#1390988 RESOLVED Ca Certificate Compliance Incident Externally Reported Incident Certificate Misissuance Opened 2017-08-16 · Closed 2023-02-22 · 78% similar
Consorci AOC: Non-BR-Compliant Certificate Issuance
#1369359 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-06-01 · Closed 2023-02-22 · 77% similar
StartCom: mis-issuance of certs with unvalidated domain names and bogus field values

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action