← Actalis cases
Bugzilla #1651651
Delayed Revocation
Actalis: Failure to revoke within 7 days: OCSP EKU issue
RESOLVED
FIXED
Actalis
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
This case concerns Actalis's failure to revoke certain intermediate CA certificates within the required 7-day timeframe as mandated by the Baseline Requirements. The issue was identified internally, leading to the initiation of this bug report. Actalis provided a detailed incident report outlining their response, including a timeline for revocation and the implementation of new security measures. As of November 5, 2020, all affected intermediate CA keys were destroyed, and their certificates were revoked, marking the resolution of the incident.
Chronology
- Destruction of affected ICA keys and revocation of their certificates.
Thread Activity
- Staff representative — This bug is related to Actalis not revoking within 7 days, as per the BR.
- Staff representative — We defined a plan of revocations of end-entity certificates issued by those ICAs.
- Staff representative — All the affected ICAs were destroyed and their certificates were revoked.
Participants
Staff representative
Mozilla representative
Community commenter
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
Actalis: delayed revocation related to inaccurate value in stateOrProvinceName
Actalis: Delayed revocation of non-BR-compliant CA Certificate within 7 days
Actalis: Failure to revoke certs within the BR required timeframe
Actalis: revocation delay for certificates issued with invalid RDN Order
DigiCert: Failure to revoke within 7 days: OCSP EKU issue
GlobalSign: Failure to revoke noncompliant ICA within 7 days
PKIoverheid: Failure to revoke within 7 days: OCSP EKU issue
Camerfirma: Failure to revoke within 7 days: OCSP EKU issue