← Actalis cases
Bugzilla #1906690
Certificate Problem Report
Actalis: CRL distribution point with ldap scheme
RESOLVED
FIXED
Actalis
AI Summary
Actalis identified that some TLS server certificates contained an ldap-scheme URL in their CRLDistributionPoints extension, which is prohibited under BRs v2.0 effective September 15, 2023. A total of 28 certificates were affected, all issued by a technically constrained SubCA. Upon discovery, Actalis promptly revoked all impacted certificates and corrected the certificate profile to prevent further misissuance. They have also implemented additional linting mechanisms to enhance compliance checks moving forward.
Chronology
- Technical checks revealed ldap scheme in CRLDistributionPoints.
- All affected certificates were revoked.
- Incident report detailing findings and actions was submitted.
- Closure summary submitted, all action items completed.
Participants
Marco Menonna
Ben Wilson
Rob
Adriano Santoni
External References
Similar Local Cases
Actalis: CRL with duplicate serial number in revokedCertificates
Entrust: EV Certificate missing Issuer’s EV Policy OID
Actalis: Incorrect OCSP Delegated Responder Certificate
Actalis: Use of CRLReason Code in Certificate Revocation
Actalis: Issusing 1024 bit certificates
Actalis: inaccurate value in stateOrProvinceName
Actalis: Certificates issued with validity period greater than 398 days
Actalis: Non BR Compliant OCSP Responder