Actalis: Issuing 1024-bit certificates due to delayed CSR processing
The bug reports that Actalis issued a certificate containing a 1024-bit key. The reporter observed a certificate chain including “CN = Actalis Authentication CA G2” and noted the presence of 1024-bit certificates. Actalis stated the certificate was issued by mistake due to an abnormal delay between certificate request and certificate issuance: the CSR was sent to their CA system in 2013 when 1024-bit keys were still allowed, and it was kept on stand-by until checks were completed. Actalis explained that they later introduced checks to block 1024-bit keys in 2014, but by then the CSR had already been ingested. Actalis revoked the identified certificate and then investigated whether similar cases occurred, stating that additional erroneous certificates were found and would be revoked. The thread concludes with Actalis confirming that all offending certificates had been revoked, and the reporter asking whether the bug could be closed as fixed. The bug is marked RESOLVED with resolution WORKSFORME.
- A 1024-bit-key certificate was issued by Actalis due to delayed CSR processing.
- Actalis revoked the mistakenly issued 1024-bit certificate and began investigating similar cases.
- Actalis completed revocation of all offending certificates.
- Roeckx representative — Reported seeing recent 1024-bit certificates from the cited certificate chain and identified the Actalis Authentication CA G2 subject.
- Staff representative — Explained the 1024-bit certificate was issued by mistake due to abnormal delay between CSR ingestion (2013) and issuance, and stated the certificate was revoked while they investigated similar situations.
- Tu-ilmenau representative — Asked Kurt to verify that the reported certificate was indeed revoked.
- Roeckx representative — Provided that the most recent one he found was revoked end of July and listed seven other still-valid certificates that should not have been valid after 1 January 2014.
- Staff representative — Said they were looking into the issue and would revoke the offending certificates as soon as possible.
- Staff representative — Reported they were progressively revoking the erroneous certificates and would post an update when done.
- Staff representative — Confirmed that all the offending certificates had been revoked.
- Mozilla representative — Asked whether the bug should be closed as fixed.