← Actalis cases
Bugzilla #1523680 Revocation Issue Incident

Actalis: Non BR Compliant OCSP Responder

RESOLVED FIXED Actalis
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The case concerns the OCSP responder for the Actalis Client Authentication CA G1, which was returning a "good" response for unknown certificates. Wayne Thayer (Fastly) filed the Bugzilla report after observing the behavior via crt.sh and asked Actalis to provide an incident report. Actalis stated that the subordinate CA only issues S/MIME certificates and initially believed the OCSP responder compliance requirement in the BR did not apply, but later acknowledged the assumption was wrong because the sub-CA is not technically constrained. Actalis modified the OCSP responder configuration so it returns an "unknown" response for unknown certificates, and the issue was confirmed fixed. Actalis also provided an incident report describing the investigation, the configuration change timeline, and an internal awareness meeting to clarify that non-technically-constrained subordinate CAs must fully comply with Mozilla requirements. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 17:59 UTC Revised: 2026-06-16 18:03 UTC Confidence: 0.50 8 comments
Chronology
  1. Wayne Thayer filed a Bugzilla report about the Actalis Client Authentication CA G1 OCSP responder returning "good" for unknown certificates.
  2. Actalis changed the OCSP responder configuration so it returns "unknown" for unknown certificates.
Thread Activity
  1. Fastly representative — Reported that the OCSP responder was returning "good" for unknown certificates and requested an incident report per Mozilla guidance.
  2. Staff representative — Said the subordinate only issues S/MIME certificates and claimed they assumed the BR OCSP requirement did not apply.
  3. Community commenter — Noted the sub-CA is technically capable of issuing TLS certificates, making the OCSP behavior potentially indistinguishable from a misissuance scenario.
  4. Staff representative — Stated they modified the OCSP responder to return "unknown" for unknown certificates.
  5. Fastly representative — Confirmed the problem was fixed and reiterated that it was a violation of Mozilla policy, requesting the incident report.
  6. Staff representative — Submitted an incident report including how they became aware, investigation steps, the configuration change timeline, and internal remediation via an awareness meeting.
  7. Fastly representative — Asked Actalis to confirm understanding that compliance applies beyond the OCSP responder requirement to all certificates signed by non-technically-constrained subordinates.
  8. Staff representative — Confirmed understanding.
Participants
Fastly representative Staff representative Community commenter
Similar Local Cases
#1536831 RESOLVED Ca Certificate Compliance Revocation Issue Remediation Tracking Opened 2019-03-20 · Closed 2023-02-22 · 75% similar
GDCA: Insufficient Serial Number Entropy
#1717357 RESOLVED Certificate Misissuance Incident Opened 2021-06-20 · Closed 2023-02-22 · 75% similar
Actalis: Issuance of intermediates after 2020-08-20 that do not comply with Mozilla Policy and the Baseline Requirements
#1426247 RESOLVED Revocation Issue Opened 2017-12-19 · Closed 2023-02-22 · 72% similar
Telia: Non-BR-Compliant OCSP Responder
#1391000 RESOLVED Ca Certificate Compliance Incident Revocation Issue Opened 2017-08-16 · Closed 2023-02-22 · 72% similar
IdenTrust: Non-BR-Compliant Certificate Issuance
#1321354 RESOLVED Revocation Issue Incident Opened 2016-11-30 · Closed 2022-11-14 · 70% similar
DocuSign France - Internal names certificates under a technically-constrained subordinate CA
#1634795 RESOLVED Revocation Issue Delayed Revocation Opened 2020-05-01 · Closed 2023-02-22 · 68% similar
Google Trust Services: Incorrect revocation data temporarily served for GTS Y3 & Y4
#1397830 RESOLVED Certificate Misissuance Revocation Issue Opened 2017-09-07 · Closed 2023-02-22 · 68% similar
EDICOM: Signing SHA-1 OCSP responses with unconstrained certificate
#1483639 RESOLVED Revocation Issue Delayed Revocation Opened 2018-08-15 · Closed 2024-06-30 · 67% similar
DigiCert / ADACOM: published expired CRLs

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action