Actalis: Issuance of certificates using private keys previously revoked for KeyCompromise
Actalis reported an incident in which it issued TLS certificates using private keys that had previously been revoked with reason code “KeyCompromise.” The issue was disclosed to Actalis by a third party, after which Actalis investigated to confirm scope and root cause. Actalis identified 18 affected certificates (DV and OV) and reported that all affected certificates were revoked, with no remaining valid certificates. Actalis stated that the incident resulted from a failure in the control mechanism intended to prevent issuance against known compromised keys, caused by a misconfiguration after maintenance that referenced an outdated compromised-key list and was not uniformly propagated to all SubCAs. Actalis also described remediation steps including restoring the correct compromised-keys configuration, revoking affected certificates, updating its revocation interface to reduce incorrect “KeyCompromise” selections, and adding monitoring/validation controls (including a monitoring mechanism and automated validation of compromised-key list update timestamp). The bug is marked RESOLVED with resolution FIXED, and Actalis requested closure after stating all action items in the incident report were completed.
- Actalis revoked a certificate with reason code KeyCompromise and later performed maintenance activity that led to a misconfiguration between the compromised-keys list and issuance systems.
- A third party reported that Actalis had issued a certificate using a private key previously revoked for KeyCompromise.
- Actalis fixed the issue and revoked the last affected certificate.
- Staff representative — Actalis provided a preliminary incident report stating it became aware of a certificate issued using a private key previously revoked with reason code KeyCompromise and that the disclosure source was third-party reporting.
- Staff representative — Actalis reported that analysis identified 16 additional active impacted certificates and that they were promptly revoked, with a full incident report to follow by February 06, 2026.
- Staff representative — Actalis posted the full incident report, stating 18 affected certificates were identified and all were revoked, and describing the timeline, root cause, and remediation/action items.
- HARICA — A commenter asked for clarification on how the incident would be prevented going forward, noting the remediation seemed to focus on detection rather than the root cause misconfiguration.
- Staff representative — Actalis responded that the action restored the preventive control by fixing configuration, added additional prevention at the configuration level (metadata timestamp and alerting), and provided an updated action plan with statuses and due dates.
- Staff representative — Actalis stated that Action Items #3 and #4 were completed and that all actions in the incident report had been fully implemented.
- Staff representative — Actalis provided a report closure summary, reiterating the incident scope and remediation, and requested closure after stating all action items were completed.
- CCADB representative — CCADB.org posted a final call for comments and indicated the incident report would be closed on approximately 2026-03-06.