← Actalis cases
Bugzilla #2012157 Certificate Misissuance

Actalis: Issuance of certificate using keys previously reported as compromised

RESOLVED FIXED Actalis
AI Summary

Actalis reported an incident involving the issuance of 18 certificates using private keys that had previously been revoked due to compromise. The issue was identified following a third-party report on January 23, 2026, leading to an internal investigation. All affected certificates were revoked by February 6, 2026. The root cause was a misconfiguration in the control mechanism that failed to prevent issuance against known compromised keys. Actalis has since implemented corrective actions and committed to strengthening its change management processes to prevent future occurrences.

Model: gpt-4o-mini Generated: 2026-06-13 21:34 UTC Confidence: 0.95
Chronology
  1. Incident reported by third party
  2. Update on analysis and identification of additional affected certificates
  3. All affected certificates revoked
  4. Incident report closure summary issued
Participants
Federica Marti dzacharo@harica.gr marco.menonna@staff.aruba.it incident-reporting@ccadb.org
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
#2016722 RESOLVED Certificate Misissuance Opened 2026-02-13 · Closed 2026-03-17 · 57% similar
PostSignum: Mis-issued certificate
#1883731 RESOLVED Certificate Misissuance Opened 2024-03-05 · Closed 2024-06-28 · 53% similar
Actalis: Certificates issued with invalid RDN order
#1927384 RESOLVED Certificate Misissuance Opened 2024-10-28 · Closed 2025-01-29 · 52% similar
iTrusChina: Issuance of certificates using keys previously reported as compromised
#2009941 RESOLVED Certificate Misissuance Opened 2026-01-13 · Closed 2026-04-06 · 51% similar
Firmaprofesional: Misissuance of TLS Subordinate CA "AC Firmaprofesional - Secure Web 2024"
#1717357 RESOLVED Certificate Misissuance Opened 2021-06-20 · Closed 2023-02-22 · 51% similar
Actalis: Issuance of intermediates after 2020-08-20 that do not comply with Mozilla Policy and the Baseline Requirements
#1534295 RESOLVED Certificate Misissuance Opened 2019-03-11 · Closed 2023-02-22 · 50% similar
Actalis: Insufficient serial number entropy
#1860750 RESOLVED Certificate Misissuance Opened 2023-10-24 · Closed 2023-11-08 · 49% similar
SwissSign: EV code in JurisdiktionStateOrProvinceName
#2032482 ASSIGNED Certificate Misissuance Opened 2026-04-16 Still Open · 49% similar
OATI: Misissuance detected by PKIMetal

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action