Actalis: Non BR Compliant OCSP Responder
The case concerns the OCSP responder for the Actalis Client Authentication CA G1, which was returning a "good" response for unknown certificates. Wayne Thayer (Fastly) filed the Bugzilla report after observing the behavior via crt.sh and asked Actalis to provide an incident report. Actalis stated that the subordinate CA only issues S/MIME certificates and initially believed the OCSP responder compliance requirement in the BR did not apply, but later acknowledged the assumption was wrong because the sub-CA is not technically constrained. Actalis modified the OCSP responder configuration so it returns an "unknown" response for unknown certificates, and the issue was confirmed fixed. Actalis also provided an incident report describing the investigation, the configuration change timeline, and an internal awareness meeting to clarify that non-technically-constrained subordinate CAs must fully comply with Mozilla requirements. The bug is marked RESOLVED with resolution FIXED.
- Wayne Thayer filed a Bugzilla report about the Actalis Client Authentication CA G1 OCSP responder returning "good" for unknown certificates.
- Actalis changed the OCSP responder configuration so it returns "unknown" for unknown certificates.
- Fastly representative — Reported that the OCSP responder was returning "good" for unknown certificates and requested an incident report per Mozilla guidance.
- Staff representative — Said the subordinate only issues S/MIME certificates and claimed they assumed the BR OCSP requirement did not apply.
- Community commenter — Noted the sub-CA is technically capable of issuing TLS certificates, making the OCSP behavior potentially indistinguishable from a misissuance scenario.
- Staff representative — Stated they modified the OCSP responder to return "unknown" for unknown certificates.
- Fastly representative — Confirmed the problem was fixed and reiterated that it was a violation of Mozilla policy, requesting the incident report.
- Staff representative — Submitted an incident report including how they became aware, investigation steps, the configuration change timeline, and internal remediation via an awareness meeting.
- Fastly representative — Asked Actalis to confirm understanding that compliance applies beyond the OCSP responder requirement to all certificates signed by non-technically-constrained subordinates.
- Staff representative — Confirmed understanding.