← Actalis cases
Bugzilla #1826713
Certificate Problem Report
Actalis: Certificates issued with validity period greater than 398 days
RESOLVED
FIXED
Actalis
AI Summary
Actalis was reported to have issued three certificates with validity periods exceeding 398 days. Upon investigation, it was confirmed that these certificates were issued by an old, offline SubCA that had not been properly decommissioned. The certificates were revoked on April 6, 2023, and interim measures were implemented to prevent future occurrences. A preliminary incident report was published detailing the timeline of events and corrective actions taken. The CA has since acknowledged the need for improved communication and compliance checks within their organization.
Chronology
- Received report of certificates exceeding validity period.
- Revoked offending certificates and modified SubCA configuration.
- Published preliminary incident report.
- Outlined measures to prevent recurrence.
Participants
Adriano Santoni
Chris Clements
External References
Similar Local Cases
Actalis: pre-certificates with “certificateHold” as the revocation reason
Actalis: incorrect CP/S Last Update date in CCADB
Actalis: Issusing 1024 bit certificates
Actalis: Non BR Compliant OCSP Responder
Actalis: inaccurate value in stateOrProvinceName
Actalis: CRL distribution point with ldap scheme
Actalis: Incorrect OCSP Delegated Responder Certificate
Actalis: Failure to revoke within 7 days: OCSP EKU issue