Actalis: two CAs with the same CRLDP
Actalis disclosed an issue involving the CRL Distribution Point (CRLDP) http://ca1.agid.gov.it/CRL used for certificates issued by its “AgID CA1” CA. The report stated that the CRL at that URL had an issuer matching one “AgID CA1” CA, while certificates appeared to be issued under two different CA identities that shared the same CRLDP, which could prevent revocation of certificates issued by the first CA. Actalis later provided an incident report describing that, during a routine regeneration/reissuance of a technically constrained non-TLS SubCA certificate on January 25, it removed the OU attribute from the CA Subject, which led to an unintended configuration where the same CRLDP appeared associated with two distinct Certificate Authorities. Actalis said it resolved the issue by revoking the problematic SubCA certificate and reissuing a new certificate with the original Subject DN, and then disclosed the updated certificate and revocation to the CCADB. Actalis stated that leaf certificates issued before January 25 could no longer be properly revoked after that date, and that no leaf certificates were compromised and no relying parties experienced service disruptions. The thread indicates that action items were addressed and Actalis requested formal closure, with Mozilla stating it would close the bug on or about 2-April-2025 unless further discussion was needed.
- Actalis reissued the “AgID CA1” technically constrained non-TLS SubCA certificate after removing the OU attribute from the CA Subject.
- Actalis revoked the problematic “AgID CA1” SubCA certificate and reissued a new “AgID CA1” certificate restoring the original Subject DN.
- Actalis reported that all identified action items had been addressed and requested continued availability for clarification.
- Actalis requested formal closure of the incident after no further developments were reported.
- Mozilla indicated it would close the bug on or about 2-April-2025 unless further discussion was needed.
- Community commenter — Andrew Ayer opened the bug after reporting that Actalis used the same CRLDP for two different CAs, which could prevent revocation of certificates issued by the first CA.
- Staff representative — Marco Menonna acknowledged the issue and stated Actalis would proceed with revocation of the second certificate.
- Staff representative — Marco Menonna posted an incident report describing how removing the OU attribute during reissuance led to CRLDP/CA identity inconsistencies, and that Actalis revoked the problematic SubCA certificate and reissued it with the original Subject DN, disclosing both to the CCADB.
- Staff representative — Marco Menonna stated that all identified action items had been addressed and that Actalis expected to maintain monitoring and processes to prevent similar incidents.
- Community commenter — Malcolm Doody noted an expectation of weekly status updates for non-closed incidents and referenced other related bugs.
- Staff representative — Marco Menonna requested formal closure, summarizing the incident, root cause, remediation, and prevention commitments.
- Mozilla representative — Ben Wilson said he would close the bug on or about Wed. 2-April-2025 unless further discussion was needed.