Actalis: Non-BR-Compliant Certificate Issuance
Actalis disclosed a compliance failure regarding the issuance of certificates containing invalid DNS names, specifically internal server names. The issue was first reported on August 13, 2017, prompting Actalis to investigate and confirm that one certificate had not been revoked as required by the Baseline Requirements (BRs). Actalis communicated with the affected customer, ENI, and agreed to revoke the certificate after ENI could replace it by September 14, 2017. The certificate was ultimately revoked on September 2, 2017, and Actalis implemented a new compliance checking system to prevent future occurrences. The case is now resolved.
- Problem report received regarding non-compliant certificate issuance.
- Offending certificate revoked.
- New compliance checking system deployed.
- Mozilla representative — Outlined the compliance issues and requested a response from Actalis.
- Staff representative — Confirmed awareness of the problem and initiated an investigation.
- Staff representative — Revoked the offending certificate.
- Staff representative — Updated on the deployment of a new compliance checking system.
- Community commenter — Marked the issue as resolved after all proposed mitigations were met.