Actalis: Issuance of intermediates after 2020-08-20 that do not comply with Mozilla Policy and the Baseline Requirements
This case involves Actalis's issuance of an intermediate CA certificate that included both `id-kp-serverAuth` and `id-kp-emailProtection`, violating Mozilla's policies and the CA/Browser Forum Baseline Requirements. The issue was first reported on June 20, 2021, leading Actalis to acknowledge the problem and commit to remedial actions. They halted further issuance of problematic certificates and initiated a timeline for revocation of the affected certificates. By September 21, 2021, Actalis successfully revoked the offending certificate, and they have since revised their internal procedures to prevent similar incidents in the future. The case is now resolved.
- Issue reported regarding non-compliance with Mozilla Policy
- Revocation of the offending AgID CA1 certificate
- Community commenter — Reported the issuance of a non-compliant intermediate CA certificate by Actalis.
- Staff representative — Acknowledged receipt of the issue and promised feedback.
- Staff representative — Provided a preliminary incident report detailing the CA's awareness and response timeline.
- Staff representative — Confirmed the revocation of the AgID CA1 certificate.
- Mozilla representative — Indicated that the bug can now be closed.