ANSSI: problematic certificates issued by AC Infrastructure
The case concerns two certificates issued by “CN=AC Infrastructure/OU=0002 110 036 035 00019/O=Ministere en charge des affaires sanitaires et sociales/C=FR”. The certificates were issued using SHA-1 and their subject alternative name extensions did not contain DNS name entries (they included an rfc822 name entry). The thread notes that Firefox would not fall back to using the subject common name for certificates with a notBefore date later than 23 August 2016. The certificates chain up to an IGC/ANSSI/DCSSI root owned by the Government of France. Kathleen Wilson asked for an explanation and a plan/timeline to resolve the SHA-1 and BR compliance issues. The response stated that the root would be removed via Bugzilla Bug #1272156, and that the root was previously constrained. The bug was later marked as resolved, with a note that the root was in the process of removal.
- Mozilla opened a CA Program bug after identifying two AC Infrastructure certificates with SHA-1 and problematic SAN contents.
- The thread stated the relevant ANSSI/DCSSI root would be removed via Bugzilla Bug #1272156.
- The bug was resolved, noting the root was in the process of removal.
- Community commenter — Reported that two AC Infrastructure certificates were issued with SHA-1 and SANs lacking DNS entries, and noted Firefox behavior changes affecting such certificates.
- Community commenter — Asked Loïc to explain why SHA-1 and non-BR-compliant SSL certificates were still being issued in the ANSSI CA hierarchy and requested a plan/timeline to resolve.
- Community commenter — Stated the root would be removed via Bugzilla Bug #1272156 and referenced that the root was previously constrained.
- Mozilla representative — Marked the issue as resolving/resolved, stating the root was in the process of removal.