Actalis: Incorrect OCSP Delegated Responder Certificate
Actalis disclosed a compliance issue regarding the issuance of OCSP Delegated Responder certificates that lacked the required `id-pkix-ocsp-nocheck` extension, as mandated by the CA/Browser Forum Baseline Requirements. The issue was initially reported on the Mozilla dev security policy mailing list, prompting Actalis to investigate and acknowledge the problem. They have since outlined a detailed incident report, including a timeline of actions taken to address the issue, such as stopping the issuance of affected certificates and planning revocations. Actalis has committed to revoking the affected certificates and implementing additional monitoring controls to prevent future occurrences. The case has been resolved with a plan in place for remediation.
- Actalis became aware of the OCSP compliance issue through a mailing list post.
- Actalis submitted a preliminary incident report detailing their investigation and planned actions.
- Actalis confirmed the implementation of monitoring controls and plans for certificate revocation.
- The bug was closed, with further discussions consolidated under a related bug for delayed revocation.
- Community commenter — Reported the issue regarding the missing OCSP extension in Actalis' certificates.
- Staff representative — Checked the OCSP responder's certificate and questioned the initial report.
- Staff representative — Provided a preliminary incident report detailing the timeline and actions taken.
- Mozilla representative — Closed the bug and directed further discussion to a related bug on delayed revocation.