← Actalis cases
Bugzilla #1651651
Certificate Problem Report
Actalis: Failure to revoke within 7 days: OCSP EKU issue
RESOLVED
FIXED
Actalis
AI Summary
Actalis faced a challenge in revoking certificates within the mandated 7-day period due to an OCSP EKU issue. The CA reported that the delay was necessary to avoid significant disruption to critical services, as revoking the affected intermediate CA certificates would impact approximately 430,000 end-entity certificates. The incident led to a comprehensive incident report and a commitment to improve internal processes and communication. The affected ICA keys were ultimately destroyed on November 5, 2020, following a detailed revocation plan.
Chronology
- Bug reported regarding failure to revoke certificates.
- Destruction of affected ICA keys completed.
Participants
Adriano Santoni
B Wilson
Ryan Sleevi
External References
Similar Local Cases
Actalis: Incorrect OCSP Delegated Responder Certificate
Actalis: inaccurate value in stateOrProvinceName
Actalis: Failure to revoke certs within the BR required timeframe
Izenpe: Failure to revoke within 5 days
Actalis: two CAs with the same CRLDP
Actalis: Certificates issued with validity period greater than 398 days
Actalis: pre-certificates with “certificateHold” as the revocation reason
Actalis: incorrect CP/S Last Update date in CCADB