Actalis: Incorrect CRLReason code used during certificate revocation
Actalis reported that, for certificate revocations referenced in Bugzilla reports #1906690 and #1883731, it had assigned an incorrect CRLReason reasonCode in the revoked certificates. Actalis stated it was notified of the potential non-compliance and then investigated, concluding that the wrong reasonCode was selected relative to the BRs (BRs v1.8.7, section 7.2.2, Table 83: CRLReasons). The impact described was that the CRLReason extension should have been #4 (superseded) but was instead set to #0 (unspecified) or #5 (cessationOfOperation) for the relevant revocations. Actalis attributed the root cause to an outdated revocation UI in its internal certificate management application that used ambiguous natural-language reason descriptions, and to a procedural gap where compliance did not formally specify the reason in the revocation request. Remediation included retroactively modifying the reasonCodes of the affected revocations in the CA database to conform to the BRs, redesigning the revocation UI to remove ambiguity and require operator confirmation, retraining revocation operators, and updating internal documentation. Actalis later stated that all action items had been completed and requested closure of the bug; Mozilla indicated it would close the bug early the following week unless additional issues arose.
- New CRL entries for specific revocation types were required to use BRs v1.8.7 revocation reason codes.
- Actalis received an email notification reporting a potential non-compliance in CRLReason code usage for revocations referenced in Bugzilla reports #1906690 and #1883731.
- Actalis acknowledged the report and began investigating the revocation reasonCode issue.
- Actalis reported retroactive correction of the affected revocation reasonCodes in its CA database as completed.
- Actalis reported completion of the remaining prevention actions (revocation UI redesign, operator retraining, and documentation updates).
- Actalis provided a closure summary stating all action items were completed and requested closure.
- Staff representative — Actalis posted a preliminary incident report stating it had used an inappropriate CRLReason revocation code for revocations tied to bugs #1906690 and #1883731.
- Staff representative — Actalis provided an incident report describing the incorrect reasonCode values, the BR requirement for #4 in the non-compliance revocation case, and a timeline and root cause analysis.
- Staff representative — Actalis reported progress, stating development of a new revocation UI was completed and being tested.
- Staff representative — Actalis stated it had completed development of the new revocation UI and was testing it thoroughly.
- Staff representative — Actalis stated all action items were completed, including retroactive reasonCode correction, UI redesign, operator retraining, and documentation updates.
- Staff representative — Adriano Santoni asked that the bug be closed due to no further updates.
- Mozilla representative — Ben Wilson requested a closing summary that described the incident, root cause(s), remediation, ongoing commitments, and attested that all action items were completed.
- Staff representative — Marco Menonna provided the incident report closure summary and requested closure, stating all action items were completed.
- Mozilla representative — Ben Wilson said he would close the bug early the following week unless additional issues or concerns were raised.