← Actalis cases
Bugzilla #1717357 Certificate Misissuance

Actalis: Issuance of intermediates after 2020-08-20 that do not comply with Mozilla Policy and the Baseline Requirements

RESOLVED FIXED Actalis
AI Summary

Actalis issued an intermediate CA certificate that included both `id-kp-serverAuth` and `id-kp-emailProtection`, violating Mozilla's policies and the Baseline Requirements. Following the discovery of this issue, Actalis acknowledged the problem and took steps to revoke the affected certificates. They also revised their internal procedures to prevent future occurrences. The incident raised concerns about potential impacts on S/MIME certificates used by Italian PEC providers, which could lead to invalid signatures on past messages. The case was resolved with the revocation of the problematic certificate.

Model: gpt-4o-mini Generated: 2026-06-13 21:25 UTC Confidence: 0.90
Chronology
  1. Bug reported regarding non-compliance with Mozilla Policy.
  2. Actalis acknowledged receipt of the issue.
  3. AgID CA1 certificate revoked as planned.
  4. Bug closed by Mozilla.
Participants
Ryan Sleevi Adriano Santoni Kathleen Wilson
Similar Local Cases
#1405817 RESOLVED Certificate Misissuance Opened 2017-10-04 · Closed 2023-02-22 · 68% similar
Actalis: Certs issued with same issuer and serial number
#1534295 RESOLVED Certificate Misissuance Opened 2019-03-11 · Closed 2023-02-22 · 67% similar
Actalis: Insufficient serial number entropy
#1386891 RESOLVED Certificate Misissuance Opened 2017-08-02 · Closed 2023-02-22 · 59% similar
Certinomis: Cross-signing of StartCom intermediate certs, and delay in reporting it in CCADB
#1391056 RESOLVED Certificate Misissuance Opened 2017-08-16 · Closed 2023-02-22 · 58% similar
NetLock: Non-BR-Compliant Certificate Issuance
#1391055 RESOLVED Certificate Misissuance Opened 2017-08-16 · Closed 2023-02-22 · 58% similar
Microsec: Non-BR-Compliant Certificate Issuance
#1390991 RESOLVED Certificate Misissuance Opened 2017-08-16 · Closed 2023-02-22 · 58% similar
Disig: Non-BR-Compliant Certificate Issuance
#1353827 RESOLVED Certificate Misissuance Opened 2017-04-05 · Closed 2023-02-22 · 58% similar
DigiCert: DigiCert issued cert with CN too long
#1397954 RESOLVED Certificate Misissuance Opened 2017-09-07 · Closed 2023-02-22 · 57% similar
DigiCert / Siemens: Insufficient Serial Number Entropy

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action