← Actalis cases
Bugzilla #1586787 Policy Compliance

Actalis: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy

RESOLVED FIXED Actalis
AI Summary

Actalis issued two intermediate certificates after January 1, 2019, that did not comply with Mozilla Policy 2.6.1, specifically lacking the required Extended Key Usage (EKU) extension. The issue was identified during an internal review in March 2019, leading to the revocation of the non-compliant certificates shortly after their issuance. Actalis has since posted a detailed incident report and taken steps to prevent similar occurrences in the future, including revising their internal procedures. The case has been resolved with all necessary actions completed.

Model: gpt-4o-mini Generated: 2026-06-13 20:01 UTC Confidence: 1.00
Chronology
  1. Intermediate CA certificate DV G1 was generated.
  2. Intermediate CA certificate EV G2 was generated.
  3. Internal review found missing EKU in EV G2.
  4. EV G2 was re-issued correctly and the defective certificate was revoked.
  5. DV G1 was revoked.
  6. Steps taken to avoid recurrence of the issue.
Participants
Ryan Sleevi Giorgio Girelli
Similar Local Cases
#1586795 RESOLVED Policy Compliance Opened 2019-10-07 · Closed 2023-02-22 · 60% similar
NetLock: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy
#1390974 RESOLVED Policy Compliance Opened 2017-08-16 · Closed 2023-02-22 · 60% similar
Actalis: Non-BR-Compliant Certificate Issuance
#1693930 RESOLVED Policy Compliance Opened 2021-02-20 · Closed 2023-02-22 · 51% similar
Microsoft PKI Services: Policy Documentation, Failure to update Subscriber Certificate Max Validity Period
#1391064 RESOLVED Policy Compliance Opened 2017-08-16 · Closed 2023-02-22 · 51% similar
SECOM: Non-BR-Compliant Certificate Issuance
#1549861 RESOLVED Policy Compliance Opened 2019-05-07 · Closed 2023-02-22 · 51% similar
Camerfirma: Outdated audit statements for intermediate certs
#1700809 RESOLVED Policy Compliance Opened 2021-03-25 · Closed 2023-02-22 · 50% similar
Microsoft PKI Services: Failure to disclose Unconstrained Intermediate within 7 Days
#1680378 RESOLVED Policy Compliance Opened 2020-12-02 · Closed 2023-02-22 · 50% similar
NetLock: Replacement of enduser certificates after the EVGL 1.7.4 self-audit
#1390996 RESOLVED Policy Compliance Opened 2017-08-16 · Closed 2023-02-22 · 50% similar
Entrust: Non-BR-Compliant Certificate Issuance

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action