← Actalis cases
Bugzilla #2049960 Common Ca Database Ccadb Disclosure Issue Incident Externally Reported Incident Opened By Ca

Actalis: missing CCADB disclosure for subordinate CA certificate

ASSIGNED Actalis
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns Actalis’s failure to disclose a subordinate CA certificate in CCADB. The issue was first reported on 2026-06-24 after Actalis received a third-party report that a subordinate CA certificate chaining to Actalis Authentication Root CA appeared to be missing from CCADB. Actalis said it completed CCADB disclosure for Actalis Code Signing CA G2 on the same day, and later disclosed Actalis Code Signing CA G1 on 2026-06-30. In the full incident report, Actalis said the affected certificate was a subordinate CA certificate used only for code signing, that no end-entity certificates were affected, and that the non-compliance ended on 2026-06-24. The bug remains open and assigned, and the latest update on 2026-09-16 said progress was aligned with the scheduled action items. Weekly updates are still being posted in the bug.

Model: gpt-5.4-mini Generated: 2026-06-24 14:50 UTC Revised: 2026-09-20 06:00 UTC Confidence: 0.98 14 comments
Chronology
  1. Actalis Code Signing CA G2 was issued by Actalis Authentication Root CA.
  2. Apple Root Program disclosure requirements became effective for pre-existing subordinate CA certificates.
  3. Actalis identified and completed CCADB disclosure for Actalis Code Signing CA G2.
  4. Actalis disclosed Actalis Code Signing CA G1 in CCADB.
Thread Activity
  1. Staff representative — Opened a preliminary incident report saying a subordinate CA certificate appeared not to be disclosed in CCADB and marked the source as third-party reported.
  2. Staff representative — Said Actalis had completed CCADB disclosure for Actalis Code Signing CA G2 and would provide further updates.
  3. Staff representative — Said internal analysis was ongoing, disclosed Actalis Code Signing CA G1 on CCADB, and said it appeared out of scope because it was revoked in 2020.
  4. Staff representative — Posted the full incident report with the timeline, impact, and policy references.
  5. Staff representative — Posted a weekly update saying the team was on track with planned action items and continuing to monitor the bug.
  6. Staff representative — Posted another weekly update saying progress was aligned with scheduled action items.
  7. Staff representative — Posted a weekly update saying progress was aligned with scheduled action items.
  8. Staff representative — Posted a weekly update saying progress was aligned with scheduled action items.
  9. Staff representative — Posted a weekly update saying progress was aligned with scheduled action items.
  10. Staff representative — Posted a weekly update saying progress was aligned with scheduled action items.
  11. Staff representative — Posted a weekly update saying progress was aligned with scheduled action items.
  12. Staff representative — Said the internal procedure governing quarterly self-audits was updated and Action Item 3 was considered complete.
  13. Staff representative — Posted a weekly update saying progress was aligned with the scheduled action items.
  14. Staff representative — Posted a weekly update saying progress was aligned with the scheduled action items.
Participants
Staff representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#2060581 ASSIGNED Ca Certificate Compliance Externally Reported Incident Certificate Misissuance Revocation Issue Opened 2026-08-04 Still Open · 88% similar
Actalis: Issuance of Server TLS Certificates with id-kp-clientAuth against CPS
#2056934 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Repository Issue Opened 2026-07-22 Still Open · 83% similar
Actalis: failure to timely update CP/CPS for AgID SubCAs
#2066489 ASSIGNED Ccadb Metadata Update Ccadb Disclosure Issue Remediation Tracking Opened By Ca Opened 2026-08-25 Still Open · 76% similar
GoDaddy: CCADB Missing Partitioned CRL URL Disclosure
#2054849 RESOLVED Ca Certificate Compliance Common Ca Database Incident Self Reported Incident Opened 2026-07-14 · Closed 2026-07-30 · 73% similar
Atos: Incorrect CRL URL in CCADB
#2055250 ASSIGNED Ca Certificate Compliance Incident Externally Reported Incident Ccadb Disclosure Issue Opened 2026-07-15 Still Open · 73% similar
D-TRUST: Incomplete Disclosure of CRL URLs
#2050850 RESOLVED Ca Certificate Compliance Common Ca Database Incident Externally Reported Incident Opened 2026-06-26 · Closed 2026-08-04 · 73% similar
Asseco DS / Certum: HTTP 404 returned by CRL Distribution Point URLs for six pre-inclusion Root CAs
#2058363 RESOLVED Common Ca Database Ccadb Disclosure Issue Incident Externally Reported Incident Opened 2026-07-28 · Closed 2026-08-29 · 72% similar
DigiCert: Blank SubCA Owner field in CCADB for cross-certificate
#2055775 RESOLVED Common Ca Database Ccadb Disclosure Issue Incident Self Reported Incident Opened 2026-07-17 · Closed 2026-09-14 · 72% similar
Asseco DS / Certum: Incomplete CRL Disclosure in CCADB

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action