← Actalis cases
Bugzilla #1649961 Self Reported Incident

Actalis: Incorrect OCSP Delegated Responder Certificate

RESOLVED FIXED Actalis
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Actalis disclosed a compliance issue regarding the issuance of OCSP Delegated Responder certificates that lacked the required `id-pkix-ocsp-nocheck` extension, as mandated by the CA/Browser Forum Baseline Requirements. The issue was initially reported on the Mozilla dev security policy mailing list, prompting Actalis to investigate and acknowledge the problem. They have since outlined a detailed incident report, including a timeline of actions taken to address the issue, such as stopping the issuance of affected certificates and planning revocations. Actalis has committed to revoking the affected certificates and implementing additional monitoring controls to prevent future occurrences. The case has been resolved with a plan in place for remediation.

Model: gpt-4o-mini Generated: 2026-06-13 21:23 UTC Revised: 2026-06-16 18:04 UTC Confidence: 0.85 17 comments
Chronology
  1. Actalis became aware of the OCSP compliance issue through a mailing list post.
  2. Actalis submitted a preliminary incident report detailing their investigation and planned actions.
  3. Actalis confirmed the implementation of monitoring controls and plans for certificate revocation.
  4. The bug was closed, with further discussions consolidated under a related bug for delayed revocation.
Thread Activity
  1. Community commenter — Reported the issue regarding the missing OCSP extension in Actalis' certificates.
  2. Staff representative — Checked the OCSP responder's certificate and questioned the initial report.
  3. Staff representative — Provided a preliminary incident report detailing the timeline and actions taken.
  4. Mozilla representative — Closed the bug and directed further discussion to a related bug on delayed revocation.
Participants
Community commenter
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
#1405817 RESOLVED Certificate Misissuance Self Reported Incident Opened 2017-10-04 · Closed 2023-02-22 · 87% similar
Actalis: Certs issued with same issuer and serial number
#1649962 RESOLVED Self Reported Incident Opened 2020-07-02 · Closed 2023-02-22 · 85% similar
SECOM: Incorrect OCSP Delegated Responder Certificate
#1390974 RESOLVED Certificate Misissuance Self Reported Incident Opened 2017-08-16 · Closed 2023-02-22 · 85% similar
Actalis: Non-BR-Compliant Certificate Issuance
#1883731 RESOLVED Self Reported Incident Opened 2024-03-05 · Closed 2024-06-28 · 83% similar
Actalis: Certificates issued with invalid RDN order
#1824319 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2023-03-24 · Closed 2023-07-20 · 81% similar
Actalis: pre-certificates with “certificateHold” as the revocation reason
#1982646 RESOLVED Self Reported Incident Opened 2025-08-12 · Closed 2025-12-01 · 81% similar
Actalis: missing CCADB disclosure for new SubCA
#2012157 RESOLVED Self Reported Incident Revocation Issue Security Incident Opened 2026-01-23 · Closed 2026-03-08 · 81% similar
Actalis: Issuance of certificate using keys previously reported as compromised
#1973238 RESOLVED Self Reported Incident Policy Document Issue Opened 2025-06-20 · Closed 2025-09-24 · 80% similar
Actalis: incorrect CP/S Last Update date in CCADB

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action