← Actalis cases
Bugzilla #1949203 Incident

Actalis: two CAs with the same CRLDP

RESOLVED FIXED Actalis
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Actalis disclosed an issue involving the CRL Distribution Point (CRLDP) http://ca1.agid.gov.it/CRL used for certificates issued by its “AgID CA1” CA. The report stated that the CRL at that URL had an issuer matching one “AgID CA1” CA, while certificates appeared to be issued under two different CA identities that shared the same CRLDP, which could prevent revocation of certificates issued by the first CA. Actalis later provided an incident report describing that, during a routine regeneration/reissuance of a technically constrained non-TLS SubCA certificate on January 25, it removed the OU attribute from the CA Subject, which led to an unintended configuration where the same CRLDP appeared associated with two distinct Certificate Authorities. Actalis said it resolved the issue by revoking the problematic SubCA certificate and reissuing a new certificate with the original Subject DN, and then disclosed the updated certificate and revocation to the CCADB. Actalis stated that leaf certificates issued before January 25 could no longer be properly revoked after that date, and that no leaf certificates were compromised and no relying parties experienced service disruptions. The thread indicates that action items were addressed and Actalis requested formal closure, with Mozilla stating it would close the bug on or about 2-April-2025 unless further discussion was needed.

Model: gpt-5.4-nano Generated: 2026-06-13 21:33 UTC Revised: 2026-06-16 18:08 UTC Confidence: 0.86 7 comments
Chronology
  1. Actalis reissued the “AgID CA1” technically constrained non-TLS SubCA certificate after removing the OU attribute from the CA Subject.
  2. Actalis revoked the problematic “AgID CA1” SubCA certificate and reissued a new “AgID CA1” certificate restoring the original Subject DN.
  3. Actalis reported that all identified action items had been addressed and requested continued availability for clarification.
  4. Actalis requested formal closure of the incident after no further developments were reported.
  5. Mozilla indicated it would close the bug on or about 2-April-2025 unless further discussion was needed.
Thread Activity
  1. Community commenter — Andrew Ayer opened the bug after reporting that Actalis used the same CRLDP for two different CAs, which could prevent revocation of certificates issued by the first CA.
  2. Staff representative — Marco Menonna acknowledged the issue and stated Actalis would proceed with revocation of the second certificate.
  3. Staff representative — Marco Menonna posted an incident report describing how removing the OU attribute during reissuance led to CRLDP/CA identity inconsistencies, and that Actalis revoked the problematic SubCA certificate and reissued it with the original Subject DN, disclosing both to the CCADB.
  4. Staff representative — Marco Menonna stated that all identified action items had been addressed and that Actalis expected to maintain monitoring and processes to prevent similar incidents.
  5. Community commenter — Malcolm Doody noted an expectation of weekly status updates for non-closed incidents and referenced other related bugs.
  6. Staff representative — Marco Menonna requested formal closure, summarizing the incident, root cause, remediation, and prevention commitments.
  7. Mozilla representative — Ben Wilson said he would close the bug on or about Wed. 2-April-2025 unless further discussion was needed.
Participants
Mm representative Staff representative Community commenter Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1717357 RESOLVED Certificate Misissuance Incident Opened 2021-06-20 · Closed 2023-02-22 · 87% similar
Actalis: Issuance of intermediates after 2020-08-20 that do not comply with Mozilla Policy and the Baseline Requirements
#2049960 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Ccadb Disclosure Issue Opened 2026-06-24 Still Open · 78% similar
Actalis: Undisclosed Subordinate CA Certificate
#1651026 RESOLVED Certificate Misissuance Incident Remediation Tracking Opened 2020-07-07 · Closed 2023-02-22 · 76% similar
Izenpe: certificate issued to internal domain
#1930759 RESOLVED Incident Opened 2024-11-12 · Closed 2025-02-12 · 75% similar
DigiCert: Domain used for CRLs and OCSP has expired
#1888371 RESOLVED Incident Opened 2024-03-28 · Closed 2024-07-09 · 75% similar
e-commerce monitoring GmbH: CRLs with mismatched issuer
#1825780 RESOLVED Incident Self Reported Incident Opened 2023-03-31 · Closed 2023-07-05 · 74% similar
Telekom Security: Improper use of a domain validation method
#1647084 RESOLVED Self Reported Incident Incident Opened 2020-06-20 · Closed 2023-02-22 · 74% similar
DigiCert / Microsoft: inconsistent disclosure of externally-operated intermediate
#1932973 RESOLVED Certificate Misissuance Incident Opened 2024-11-22 · Closed 2025-04-07 · 74% similar
SSL.com: CAA Empty set handling results in Wildcard issuance

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action