Actalis: Delayed revocation of non-BR-compliant CA Certificate within 7 days
This case concerns Actalis revocation timing for a subordinate CA certificate that was found not to comply with Mozilla Baseline Requirements. The problematic certificate was issued for a technically constrained subordinate CA (“AgID CA1”) under the Actalis Root, and Actalis was expected to revoke it within 7 days of being made aware of the problem. In the thread, Actalis explained that while TLS issuance under that subordinate CA had already been stopped and residual TLS certificates were revoked, the situation for S/MIME certificates was different because they are used to sign PEC messages in Italy’s certified e-mail system. Mozilla staff asked for additional analysis of the scope and impact (including how many PEC/subscriber certificates were involved) and for more detail on long-term measures to prevent future revocation delays. Actalis’ colleague provided context on the PEC system and stated that the primary corrective action was to replace the subordinate CA with a new “AgID CA” constrained to `id-kp-emailProtection` and `id-kp-clientAuth`, noting concerns about invalidating PEC messages if revocation occurs. The bug was later closed as fixed, along with Bug 1717357, on 1-Oct-2021.
- Actalis issued a subordinate CA certificate for “AgID CA1” under the Actalis Root.
- Mozilla Baseline Requirements v1.7.1 (August 2020) began forbidding subordinate CA certificates from including both serverAuth and emailProtection in EKU.
- Actalis became aware that the “AgID CA1” subordinate CA certificate was not BR-compliant and initiated the incident response described in the bug.
- Mozilla staff requested additional scope/impact analysis and longer-term prevention details.
- Actalis’ colleague provided PEC system context and described the primary corrective action to replace the CA with a constrained “AgID CA.”
- Mozilla closed this bug along with Bug 1717357.
- Staff representative — Opened the bug explaining that Actalis did not revoke the non-BR-compliant subordinate CA certificate within 7 days as required, and provided a detailed rationale and response timeline.
- Community commenter — Noted that the bug appears to reflect a request for OneCRL and referenced prior discussion about notifying Mozilla of the request.
- Staff representative — Responded to Mozilla’s concerns, including discussion of corrective actions and justification for the revocation delay.
- Community commenter — Asked for more analysis of scope/impact (number of PEC/subscriber certificates) and more detail on long-term steps to prevent future delays, including whether the primary corrective action was replacing the CA with one constrained to `id-kp-emailProtection`.
- Staff representative — Provided PEC system details (authorized service providers and active S/MIME certificates) and stated the primary corrective action was replacing the CA with a new constrained “AgID CA,” explaining why revocation could invalidate PEC messages.
- Mozilla representative — Closed the bug along with Bug 1717357 on 1-Oct-2021.