← Actalis cases
Bugzilla #1586787 Certificate Misissuance

Actalis: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy

RESOLVED FIXED Actalis
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Ryan Sleevi opened this bug after a spot-check of Mozilla Policy Compliance found that Actalis issued two intermediate CA certificates after 2019-01-01 that did not comply with Mozilla Policy 2.6.1, specifically lacking an EKU extension and involving incorrect KeyPurposeId combinations. The two certificates were https://crt.sh/?id=1283820374 (issued 2019-03-13, revoked 2019-03-19) and https://crt.sh/?id=1287935739 (issued 2019-03-12, revoked 2019-03-29). Giorgio Girelli responded that Actalis would post an incident report consistent with https://wiki.mozilla.org/CA/Responding_To_An_Incident. Actalis later posted an incident report describing internal detection in March 2019 during a test phase, re-issuing the affected intermediates correctly, and revoking the defective ones. The report states the issue was caused by an operator unintentionally selecting an incorrect certificate profile and that verification at the time relied on a checklist that did not explicitly ask to check the relevant parameter(s). The incident report also says Actalis took steps to avoid recurrence and corrected its internal procedure for incident handling. A later comment from w**********r@fastly.com stated that remediation is complete, and the bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 20:01 UTC Revised: 2026-06-16 18:04 UTC Confidence: 0.90 6 comments
Chronology
  1. Actalis generated an intermediate CA certificate (DV G1) that later was found to be missing the required EKU extension.
  2. Actalis generated an intermediate CA certificate (EV G2) that later was found to be missing the required EKU extension.
  3. Actalis’ internal review identified the missing-EKU problem in the EV G2 certificate and requested corrective re-issuance and revocation.
  4. Actalis re-issued the EV G2 correctly and revoked the defective EV G2; it also identified the same problem in the DV G1 certificate and requested corrective re-issuance and revocation.
  5. Actalis revoked the defective DV G1 certificate after corrective actions.
  6. Ryan Sleevi filed the bug after discovering the non-compliant intermediate issuance during a Mozilla policy spot-check.
  7. Actalis posted an incident report describing detection, corrective actions, and prevention steps.
  8. A participant stated remediation was complete.
Thread Activity
  1. Community commenter — Ryan Sleevi reported that Actalis issued and then revoked two intermediate certificates that lacked an EKU extension, requesting an incident report consistent with Mozilla guidance.
  2. Staff representative — Giorgio Girelli said he was collecting information and would post an incident report consistent with the Mozilla incident-response wiki soon.
  3. Staff representative — Giorgio Girelli posted a detailed incident report including how the problem was detected, a timeline of re-issuance and revocation, and steps taken to avoid recurrence.
  4. Community commenter — Ryan Sleevi thanked Giorgio for the report and asked about improving incident-handling expectations and whether Actalis reviewed other CA incidents and considered contributing a linter.
  5. Staff representative — Giorgio Girelli discussed clarifying policy language about test-phase vs in-use distinctions and said Actalis reviews past incidents; he also said staff are not familiar with linter tool programming languages but may contribute later.
  6. Fastly representative — w**********r@fastly.com stated that remediation is complete.
Participants
Community commenter Staff representative Fastly representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1717357 RESOLVED Certificate Misissuance Incident Opened 2021-06-20 · Closed 2023-02-22 · 88% similar
Actalis: Issuance of intermediates after 2020-08-20 that do not comply with Mozilla Policy and the Baseline Requirements
#1390974 RESOLVED Certificate Misissuance Self Reported Incident Opened 2017-08-16 · Closed 2023-02-22 · 87% similar
Actalis: Non-BR-Compliant Certificate Issuance
#1648997 RESOLVED Certificate Misissuance Opened 2020-06-28 · Closed 2023-02-22 · 87% similar
Actalis: inaccurate value in stateOrProvinceName
#1405817 RESOLVED Certificate Misissuance Self Reported Incident Opened 2017-10-04 · Closed 2023-02-22 · 80% similar
Actalis: Certs issued with same issuer and serial number
#1906690 RESOLVED Certificate Misissuance Opened 2024-07-08 · Closed 2025-03-18 · 80% similar
Actalis: CRL distribution point with ldap scheme
#1914419 RESOLVED Certificate Misissuance Opened 2024-08-22 · Closed 2025-02-04 · 80% similar
Actalis: Use of CRLReason Code in Certificate Revocation
#1586795 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-10-07 · Closed 2023-02-22 · 78% similar
NetLock: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy
#1551364 RESOLVED Certificate Misissuance Opened 2019-05-14 · Closed 2023-02-22 · 77% similar
SwissSign: "Some-State" in stateOrProvinceName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action