← Actalis cases
Bugzilla #2012157 Self Reported Incident Revocation Issue Security Incident

Actalis: Issuance of certificates using private keys previously revoked for KeyCompromise

RESOLVED FIXED Actalis
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Actalis reported an incident in which it issued TLS certificates using private keys that had previously been revoked with reason code “KeyCompromise.” The issue was disclosed to Actalis by a third party, after which Actalis investigated to confirm scope and root cause. Actalis identified 18 affected certificates (DV and OV) and reported that all affected certificates were revoked, with no remaining valid certificates. Actalis stated that the incident resulted from a failure in the control mechanism intended to prevent issuance against known compromised keys, caused by a misconfiguration after maintenance that referenced an outdated compromised-key list and was not uniformly propagated to all SubCAs. Actalis also described remediation steps including restoring the correct compromised-keys configuration, revoking affected certificates, updating its revocation interface to reduce incorrect “KeyCompromise” selections, and adding monitoring/validation controls (including a monitoring mechanism and automated validation of compromised-key list update timestamp). The bug is marked RESOLVED with resolution FIXED, and Actalis requested closure after stating all action items in the incident report were completed.

Model: gpt-5.4-nano Generated: 2026-06-13 21:34 UTC Revised: 2026-06-16 18:09 UTC Confidence: 0.90 8 comments
Chronology
  1. Actalis revoked a certificate with reason code KeyCompromise and later performed maintenance activity that led to a misconfiguration between the compromised-keys list and issuance systems.
  2. A third party reported that Actalis had issued a certificate using a private key previously revoked for KeyCompromise.
  3. Actalis fixed the issue and revoked the last affected certificate.
Thread Activity
  1. Staff representative — Actalis provided a preliminary incident report stating it became aware of a certificate issued using a private key previously revoked with reason code KeyCompromise and that the disclosure source was third-party reporting.
  2. Staff representative — Actalis reported that analysis identified 16 additional active impacted certificates and that they were promptly revoked, with a full incident report to follow by February 06, 2026.
  3. Staff representative — Actalis posted the full incident report, stating 18 affected certificates were identified and all were revoked, and describing the timeline, root cause, and remediation/action items.
  4. HARICA — A commenter asked for clarification on how the incident would be prevented going forward, noting the remediation seemed to focus on detection rather than the root cause misconfiguration.
  5. Staff representative — Actalis responded that the action restored the preventive control by fixing configuration, added additional prevention at the configuration level (metadata timestamp and alerting), and provided an updated action plan with statuses and due dates.
  6. Staff representative — Actalis stated that Action Items #3 and #4 were completed and that all actions in the incident report had been fully implemented.
  7. Staff representative — Actalis provided a report closure summary, reiterating the incident scope and remediation, and requested closure after stating all action items were completed.
  8. CCADB representative — CCADB.org posted a final call for comments and indicated the incident report would be closed on approximately 2026-03-06.
Participants
Staff representative HARICA CCADB representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1973238 RESOLVED Self Reported Incident Policy Document Issue Opened 2025-06-20 · Closed 2025-09-24 · 96% similar
Actalis: incorrect CP/S Last Update date in CCADB
#2049960 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Ccadb Disclosure Issue Opened 2026-06-24 Still Open · 89% similar
Actalis: Undisclosed Subordinate CA Certificate
#1883731 RESOLVED Self Reported Incident Opened 2024-03-05 · Closed 2024-06-28 · 89% similar
Actalis: Certificates issued with invalid RDN order
#1824319 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2023-03-24 · Closed 2023-07-20 · 88% similar
Actalis: pre-certificates with “certificateHold” as the revocation reason
#1982646 RESOLVED Self Reported Incident Opened 2025-08-12 · Closed 2025-12-01 · 88% similar
Actalis: missing CCADB disclosure for new SubCA
#1972887 RESOLVED Self Reported Incident Revocation Issue Opened 2025-06-18 · Closed 2025-09-30 · 84% similar
A-Trust: TLS non-compliance detected during linter implementation
#1405817 RESOLVED Certificate Misissuance Self Reported Incident Opened 2017-10-04 · Closed 2023-02-22 · 82% similar
Actalis: Certs issued with same issuer and serial number
#2012274 RESOLVED Self Reported Incident Certificate Misissuance Revocation Issue Opened 2026-01-24 · Closed 2026-03-08 · 81% similar
Chunghwa Telecom: Issuance of certificate using keys previously reported as compromised

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action