← Actalis cases
Bugzilla #1649961
Certificate Problem Report
Actalis: Incorrect OCSP Delegated Responder Certificate
RESOLVED
FIXED
Actalis
AI Summary
Actalis was reported for issuing OCSP Delegated Responder certificates without the required 'id-pkix-ocsp-nocheck' extension, violating Baseline Requirements. The issue was identified through a post on the Mozilla dev-security-policy mailing list. Actalis initially disputed the claim but later acknowledged the problem and initiated an investigation. They committed to revoking the affected certificates and implementing monitoring controls to prevent future occurrences. The case was resolved with a plan for revocation and key destruction by November 2020.
Chronology
- Issue reported on Mozilla mailing list.
- Actalis begins investigation.
- Preliminary incident report submitted.
- Monitoring controls discussed.
- Bug closed, further discussion consolidated under related bug.
Participants
Ryan Sleevi
Adriano Santoni
Ben Wilson
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
Actalis: inaccurate value in stateOrProvinceName
Actalis: CRL distribution point with ldap scheme
Actalis: Failure to revoke within 7 days: OCSP EKU issue
Actalis: Use of CRLReason Code in Certificate Revocation
GoDaddy: Failure to revoke certificate with compromised key within 24 hours
Actalis: Non BR Compliant OCSP Responder
Actalis: incorrect CP/S Last Update date in CCADB
Actalis: CRL with duplicate serial number in revokedCertificates