← Actalis cases
Bugzilla #1523680
Certificate Problem Report
Actalis: Non BR Compliant OCSP Responder
RESOLVED
FIXED
Actalis
AI Summary
The OCSP responder for Actalis Client Authentication CA G1 was initially returning a 'good' response for unknown certificates, violating Mozilla's policy. After being notified of the issue, Actalis promptly modified the OCSP responder's configuration to return 'unknown' for such cases. An incident report was submitted detailing the timeline of actions taken, confirming no certificate mis-issuance occurred. Actalis acknowledged the need for compliance with Mozilla's requirements for all certificates issued by non-technically-constrained subordinate CAs.
Chronology
- Bug filed by Wayne Thayer regarding OCSP responder compliance.
- Actalis began investigations into the issue.
- Configuration of OCSP responder changed to return 'unknown' for unknown certificates.
- Confirmation received that the issue was resolved.
Participants
Wayne Thayer
Adriano Santoni
External References
Similar Local Cases
Actalis: pre-certificates with “certificateHold” as the revocation reason
Actalis: Certificates issued with validity period greater than 398 days
Actalis: Incorrect OCSP Delegated Responder Certificate
Actalis: CRL distribution point with ldap scheme
Actalis: Issusing 1024 bit certificates
Actalis: incorrect CP/S Last Update date in CCADB
Actalis: CRL with duplicate serial number in revokedCertificates
Add Actalis intermediate certs to OneCRL