Actalis: Certs issued with same issuer and serial number
Kathleen Wilson reported that Actalis had issued intermediate certificates with the same issuer and serial number, which she stated is a violation of the BR serial number uniqueness requirement and RFC5280 section 4.1.2.2. The report identified the issuer and the affected certificates and noted they were not revoked at the time of the report. Actalis responded with an incident report and described immediate action: revocation of the affected SubCA certificate was scheduled for Oct 4, EOB, along with remedial steps to prevent recurrence (including updating SubCA post-processing software, updating the reference manual, upgrading Root CA software to remove the need for post-processing, and holding an awareness meeting). Actalis later confirmed that the affected SubCA certificate was revoked on Oct 4, the SubCA post-processing software was updated on the same day, and an awareness meeting was held on Oct 5. Actalis also stated that it deployed an upgraded Root CA software in production near the end of 2017, tested it, and decommissioned the legacy SubCA post-processing tool. A Mozilla participant confirmed that both certificates were revoked and that action items appeared completed, and closed the issue.
- Actalis issued a SubCA certificate for Unicredit (as referenced in the thread).
- Actalis revoked the affected SubCA certificate and updated its SubCA post-processing software.
- Actalis held an awareness meeting with CA staff and its internal auditor.
- Actalis deployed upgraded Root CA software to production near the end of 2017 and decommissioned the legacy SubCA post-processing tool.
- Mozilla representative — Reported that Actalis issued intermediate certificates with the same issuer and serial number and requested an incident report and CCADB records/explanation.
- Mozilla representative — Requested adding records for the certs to the CCADB and explaining why they were not previously disclosed.
- Mozilla representative — Noted that the certs are technically constrained and provided an initial incident report link plus immediate action and remedial actions.
- Staff representative — Provided an update confirming revocation occurred on Oct 4, SubCA post-processing software was fixed, an awareness meeting was held, and Root CA software upgrade paths were being studied.
- Mozilla representative — Asked for an update on the situation.
- Staff representative — Stated that the Root CA software upgrade procedure was defined in test and scheduled for production by end of year.
- Staff representative — Confirmed the upgraded Root CA software was deployed in production near end of 2017, tested successfully, and the legacy SubCA post-processing tool was decommissioned.
- Fastly representative — Confirmed both certificates are revoked and that action items appeared completed, and closed the issue.