← Government of France (ANSSI, DCSSI) cases
Bugzilla #1301731 Root Removal Certificate Misissuance

ANSSI: problematic certificates issued by AC Infrastructure

RESOLVED WONTFIX Government of France (ANSSI, DCSSI)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The case concerns two certificates issued by “CN=AC Infrastructure/OU=0002 110 036 035 00019/O=Ministere en charge des affaires sanitaires et sociales/C=FR”. The certificates were issued using SHA-1 and their subject alternative name extensions did not contain DNS name entries (they included an rfc822 name entry). The thread notes that Firefox would not fall back to using the subject common name for certificates with a notBefore date later than 23 August 2016. The certificates chain up to an IGC/ANSSI/DCSSI root owned by the Government of France. Kathleen Wilson asked for an explanation and a plan/timeline to resolve the SHA-1 and BR compliance issues. The response stated that the root would be removed via Bugzilla Bug #1272156, and that the root was previously constrained. The bug was later marked as resolved, with a note that the root was in the process of removal.

Model: gpt-5.4-nano Generated: 2026-06-13 14:05 UTC Revised: 2026-06-16 18:29 UTC Confidence: 0.84 4 comments
Chronology
  1. Mozilla opened a CA Program bug after identifying two AC Infrastructure certificates with SHA-1 and problematic SAN contents.
  2. The thread stated the relevant ANSSI/DCSSI root would be removed via Bugzilla Bug #1272156.
  3. The bug was resolved, noting the root was in the process of removal.
Thread Activity
  1. Community commenter — Reported that two AC Infrastructure certificates were issued with SHA-1 and SANs lacking DNS entries, and noted Firefox behavior changes affecting such certificates.
  2. Community commenter — Asked Loïc to explain why SHA-1 and non-BR-compliant SSL certificates were still being issued in the ANSSI CA hierarchy and requested a plan/timeline to resolve.
  3. Community commenter — Stated the root would be removed via Bugzilla Bug #1272156 and referenced that the root was previously constrained.
  4. Mozilla representative — Marked the issue as resolving/resolved, stating the root was in the process of removal.
Participants
Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1420855 RESOLVED Root Removal Opened 2017-11-27 · Closed 2022-11-14 · 66% similar
Remove CA Disig Root R1
#605187 RESOLVED Root Removal Opened 2010-10-18 · Closed 2022-11-14 · 66% similar
Remove AOL Time Warner root certs
#1640819 RESOLVED Root Removal Opened 2020-05-26 · Closed 2022-11-14 · 60% similar
Remove CN=LuxTrust Global Root 2 root cert
#2024749 ASSIGNED Root Removal Opened 2026-03-19 Still Open · 58% similar
Firmaprofesional: Request for voluntary root removal - FIRMAPROFESIONAL CA ROOT-A WEB
#1195115 RESOLVED Certificate Misissuance Opened 2015-08-16 · Closed 2022-11-14 · 57% similar
Swisscom: certificates without DNS names in subjectAltName
#487150 RESOLVED Root Removal Opened 2009-04-07 · Closed 2022-11-14 · 56% similar
Removal request of StartCom 1024 bit CA root
#1034834 RESOLVED Certificate Misissuance Opened 2014-07-05 · Closed 2022-11-14 · 55% similar
Visa: Issuing 1024 bit certificates
#988633 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2014-03-26 · Closed 2023-02-22 · 55% similar
GoDaddy: improperly encoded certificate issued by Go Daddy Secure Certification Authority

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action