← Actalis cases
Bugzilla #1982646
Certificate Problem Report
Actalis: missing CCADB disclosure for new SubCA
RESOLVED
FIXED
Actalis
AI Summary
Actalis faced a compliance issue when a newly-created SubCA issued publicly-trusted certificates before being disclosed on CCADB. The incident was reported by a third party on August 11, 2025, after the SubCA had been operational since July 30, 2025. Actalis acknowledged the oversight, which stemmed from outdated internal procedures that did not reflect recent policy changes. The company has since updated its Certificate Management Policy and related processes to ensure compliance with CCADB requirements and prevent future occurrences.
Chronology
- New SubCA issued publicly-trusted certificates.
- Incident reported by third party; disclosure of SubCA completed.
- Incident report closure requested.
Participants
Nicolò Papi
External References
Similar Local Cases
Actalis: incorrect CP/S Last Update date in CCADB
Actalis: Issusing 1024 bit certificates
Actalis: Non BR Compliant OCSP Responder
Actalis: inaccurate value in stateOrProvinceName
Actalis: Incorrect OCSP Delegated Responder Certificate
Actalis: Certificates issued with validity period greater than 398 days
Actalis: revocation delay for certificates issued with invalid RDN Order
Actalis: Failure to revoke certs within the BR required timeframe