Actalis: Certificates issued with validity period greater than 398 days
Actalis reported that it received an external report that three of its certificates had a validity period greater than 398 days. Actalis investigated and determined the certificates were issued by an old offline SubCA used for a few websites, and that the SubCA configuration had not been updated when the 398-day maximum validity requirement became effective in September 2020. Actalis revoked the three certificates and continued its investigations. As an interim preventative measure, Actalis modified the configuration of the involved SubCA to only allow 1-year validity for TLS certificates. In its investigation results, Actalis stated that the incident was caused by incorrect assumptions and misunderstandings between internal departments, and that alerting from a post-issuance linting script had not been delivered due to a later internal email services change. Actalis also described additional remediation steps, including modifying certificate profiles, holding a meeting with involved departments, formally decommissioning the SubCA for any purpose, and deactivating it so further issuance would be impossible. The bug is marked RESOLVED with resolution FIXED, and Mozilla indicated it would close the case unless further discussion was required.
- The oldest affected certificate was issued with a validity period exceeding 398 days.
- The most recent affected certificate was issued with a validity period exceeding 398 days.
- Actalis revoked the three offending certificates and modified the involved SubCA to restrict TLS certificate validity to 1 year.
- Actalis held a meeting with involved departments to share the incident and remediation lessons.
- Mozilla planned to close the bug unless further discussion was required.
- Staff representative — Actalis said it received a report that three Actalis certificates had validity periods greater than 398 days and that it had started investigations.
- Staff representative — Actalis listed three affected certificates and stated it had revoked them per BR 4.9.1.1 while investigations continued.
- Staff representative — Actalis provided a preliminary incident report describing how it became aware of the issue, its timeline, and interim measures.
- Staff representative — Actalis shared investigation results, root cause details, and planned measures to prevent recurrence.
- Google representative — Mozilla asked what lessons learned could be shared and whether anything from the April 17 meeting should be shared with the community.
- Staff representative — Actalis responded with lessons learned about avoiding misunderstandings, decommissioning, and alerting/testing, and discussed outcomes from the April 17 meeting.
- Staff representative — Actalis stated there were no further updates.
- Staff representative — Actalis stated there were no further updates.
- Mozilla representative — Mozilla stated it would close the bug on or about 19-Jul-2023 unless further discussion was required.