← Actalis cases
Bugzilla #1405817 Certificate Misissuance Self Reported Incident

Actalis: Certs issued with same issuer and serial number

RESOLVED FIXED Actalis
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Kathleen Wilson reported that Actalis had issued intermediate certificates with the same issuer and serial number, which she stated is a violation of the BR serial number uniqueness requirement and RFC5280 section 4.1.2.2. The report identified the issuer and the affected certificates and noted they were not revoked at the time of the report. Actalis responded with an incident report and described immediate action: revocation of the affected SubCA certificate was scheduled for Oct 4, EOB, along with remedial steps to prevent recurrence (including updating SubCA post-processing software, updating the reference manual, upgrading Root CA software to remove the need for post-processing, and holding an awareness meeting). Actalis later confirmed that the affected SubCA certificate was revoked on Oct 4, the SubCA post-processing software was updated on the same day, and an awareness meeting was held on Oct 5. Actalis also stated that it deployed an upgraded Root CA software in production near the end of 2017, tested it, and decommissioned the legacy SubCA post-processing tool. A Mozilla participant confirmed that both certificates were revoked and that action items appeared completed, and closed the issue.

Model: gpt-5.4-nano Generated: 2026-06-13 17:11 UTC Revised: 2026-06-16 18:02 UTC Confidence: 0.84 8 comments
Chronology
  1. Actalis issued a SubCA certificate for Unicredit (as referenced in the thread).
  2. Actalis revoked the affected SubCA certificate and updated its SubCA post-processing software.
  3. Actalis held an awareness meeting with CA staff and its internal auditor.
  4. Actalis deployed upgraded Root CA software to production near the end of 2017 and decommissioned the legacy SubCA post-processing tool.
Thread Activity
  1. Mozilla representative — Reported that Actalis issued intermediate certificates with the same issuer and serial number and requested an incident report and CCADB records/explanation.
  2. Mozilla representative — Requested adding records for the certs to the CCADB and explaining why they were not previously disclosed.
  3. Mozilla representative — Noted that the certs are technically constrained and provided an initial incident report link plus immediate action and remedial actions.
  4. Staff representative — Provided an update confirming revocation occurred on Oct 4, SubCA post-processing software was fixed, an awareness meeting was held, and Root CA software upgrade paths were being studied.
  5. Mozilla representative — Asked for an update on the situation.
  6. Staff representative — Stated that the Root CA software upgrade procedure was defined in test and scheduled for production by end of year.
  7. Staff representative — Confirmed the upgraded Root CA software was deployed in production near end of 2017, tested successfully, and the legacy SubCA post-processing tool was decommissioned.
  8. Fastly representative — Confirmed both certificates are revoked and that action items appeared completed, and closed the issue.
Participants
Community commenter
Similar Local Cases
#1390974 RESOLVED Certificate Misissuance Self Reported Incident Opened 2017-08-16 · Closed 2023-02-22 · 88% similar
Actalis: Non-BR-Compliant Certificate Issuance
#1649961 RESOLVED Self Reported Incident Opened 2020-07-02 · Closed 2023-02-22 · 87% similar
Actalis: Incorrect OCSP Delegated Responder Certificate
#2012157 RESOLVED Self Reported Incident Revocation Issue Security Incident Opened 2026-01-23 · Closed 2026-03-08 · 82% similar
Actalis: Issuance of certificate using keys previously reported as compromised
#1883731 RESOLVED Self Reported Incident Opened 2024-03-05 · Closed 2024-06-28 · 81% similar
Actalis: Certificates issued with invalid RDN order
#1586787 RESOLVED Certificate Misissuance Opened 2019-10-07 · Closed 2023-02-22 · 80% similar
Actalis: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy
#1717357 RESOLVED Certificate Misissuance Incident Opened 2021-06-20 · Closed 2023-02-22 · 80% similar
Actalis: Issuance of intermediates after 2020-08-20 that do not comply with Mozilla Policy and the Baseline Requirements
#1824319 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2023-03-24 · Closed 2023-07-20 · 80% similar
Actalis: pre-certificates with “certificateHold” as the revocation reason
#1906690 RESOLVED Certificate Misissuance Opened 2024-07-08 · Closed 2025-03-18 · 80% similar
Actalis: CRL distribution point with ldap scheme

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action