← Actalis cases
Bugzilla #1826713 Ca Certificate Compliance Certificate Misissuance

Actalis: Certificates issued with validity period greater than 398 days

RESOLVED FIXED Actalis
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Actalis reported that it received an external report that three of its certificates had a validity period greater than 398 days. Actalis investigated and determined the certificates were issued by an old offline SubCA used for a few websites, and that the SubCA configuration had not been updated when the 398-day maximum validity requirement became effective in September 2020. Actalis revoked the three certificates and continued its investigations. As an interim preventative measure, Actalis modified the configuration of the involved SubCA to only allow 1-year validity for TLS certificates. In its investigation results, Actalis stated that the incident was caused by incorrect assumptions and misunderstandings between internal departments, and that alerting from a post-issuance linting script had not been delivered due to a later internal email services change. Actalis also described additional remediation steps, including modifying certificate profiles, holding a meeting with involved departments, formally decommissioning the SubCA for any purpose, and deactivating it so further issuance would be impossible. The bug is marked RESOLVED with resolution FIXED, and Mozilla indicated it would close the case unless further discussion was required.

Model: gpt-5.4-nano Generated: 2026-06-13 21:28 UTC Revised: 2026-06-16 18:06 UTC Confidence: 0.86 9 comments
Chronology
  1. The oldest affected certificate was issued with a validity period exceeding 398 days.
  2. The most recent affected certificate was issued with a validity period exceeding 398 days.
  3. Actalis revoked the three offending certificates and modified the involved SubCA to restrict TLS certificate validity to 1 year.
  4. Actalis held a meeting with involved departments to share the incident and remediation lessons.
  5. Mozilla planned to close the bug unless further discussion was required.
Thread Activity
  1. Staff representative — Actalis said it received a report that three Actalis certificates had validity periods greater than 398 days and that it had started investigations.
  2. Staff representative — Actalis listed three affected certificates and stated it had revoked them per BR 4.9.1.1 while investigations continued.
  3. Staff representative — Actalis provided a preliminary incident report describing how it became aware of the issue, its timeline, and interim measures.
  4. Staff representative — Actalis shared investigation results, root cause details, and planned measures to prevent recurrence.
  5. Google representative — Mozilla asked what lessons learned could be shared and whether anything from the April 17 meeting should be shared with the community.
  6. Staff representative — Actalis responded with lessons learned about avoiding misunderstandings, decommissioning, and alerting/testing, and discussed outcomes from the April 17 meeting.
  7. Staff representative — Actalis stated there were no further updates.
  8. Staff representative — Actalis stated there were no further updates.
  9. Mozilla representative — Mozilla stated it would close the bug on or about 19-Jul-2023 unless further discussion was required.
Participants
Staff representative Google representative Mozilla representative DigiCert
Similar Local Cases
#1034835 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2014-07-05 · Closed 2022-11-14 · 99% similar
Actalis: Issusing 1024 bit certificates
#1667518 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2020-09-26 · Closed 2023-02-22 · 80% similar
QuoVadis: Incorrect keyUsage for ECC certificate
#1744518 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-12-06 · Closed 2023-02-22 · 79% similar
GlobalSign: EV certificates with serialNumber Government Entity and businessCategory Private Organization
#1760311 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-03-18 · Closed 2023-02-22 · 79% similar
GlobalSign: OCSP responder certificates with more than 64 characters in CN
#1727963 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-08-28 · Closed 2023-02-22 · 79% similar
DigiCert: Truncation of Registration Number
#1734131 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-10-05 · Closed 2023-02-22 · 79% similar
SwissSign: wrong address in EV certificate
#1851164 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2023-09-01 · Closed 2023-09-22 · 79% similar
SwissSign: S/MIME wrong key Usage
#1653504 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2020-07-17 · Closed 2023-02-22 · 79% similar
Sectigo: Certificates with RSA keys where modulus is not divisible by 8

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action