Actalis: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy
Ryan Sleevi opened this bug after a spot-check of Mozilla Policy Compliance found that Actalis issued two intermediate CA certificates after 2019-01-01 that did not comply with Mozilla Policy 2.6.1, specifically lacking an EKU extension and involving incorrect KeyPurposeId combinations. The two certificates were https://crt.sh/?id=1283820374 (issued 2019-03-13, revoked 2019-03-19) and https://crt.sh/?id=1287935739 (issued 2019-03-12, revoked 2019-03-29). Giorgio Girelli responded that Actalis would post an incident report consistent with https://wiki.mozilla.org/CA/Responding_To_An_Incident. Actalis later posted an incident report describing internal detection in March 2019 during a test phase, re-issuing the affected intermediates correctly, and revoking the defective ones. The report states the issue was caused by an operator unintentionally selecting an incorrect certificate profile and that verification at the time relied on a checklist that did not explicitly ask to check the relevant parameter(s). The incident report also says Actalis took steps to avoid recurrence and corrected its internal procedure for incident handling. A later comment from w**********r@fastly.com stated that remediation is complete, and the bug is marked RESOLVED with resolution FIXED.
- Actalis generated an intermediate CA certificate (DV G1) that later was found to be missing the required EKU extension.
- Actalis generated an intermediate CA certificate (EV G2) that later was found to be missing the required EKU extension.
- Actalis’ internal review identified the missing-EKU problem in the EV G2 certificate and requested corrective re-issuance and revocation.
- Actalis re-issued the EV G2 correctly and revoked the defective EV G2; it also identified the same problem in the DV G1 certificate and requested corrective re-issuance and revocation.
- Actalis revoked the defective DV G1 certificate after corrective actions.
- Ryan Sleevi filed the bug after discovering the non-compliant intermediate issuance during a Mozilla policy spot-check.
- Actalis posted an incident report describing detection, corrective actions, and prevention steps.
- A participant stated remediation was complete.
- Community commenter — Ryan Sleevi reported that Actalis issued and then revoked two intermediate certificates that lacked an EKU extension, requesting an incident report consistent with Mozilla guidance.
- Staff representative — Giorgio Girelli said he was collecting information and would post an incident report consistent with the Mozilla incident-response wiki soon.
- Staff representative — Giorgio Girelli posted a detailed incident report including how the problem was detected, a timeline of re-issuance and revocation, and steps taken to avoid recurrence.
- Community commenter — Ryan Sleevi thanked Giorgio for the report and asked about improving incident-handling expectations and whether Actalis reviewed other CA incidents and considered contributing a linter.
- Staff representative — Giorgio Girelli discussed clarifying policy language about test-phase vs in-use distinctions and said Actalis reviews past incidents; he also said staff are not familiar with linter tool programming languages but may contribute later.
- Fastly representative — w**********r@fastly.com stated that remediation is complete.