Actalis third-party incident report: TLS server certificates issued with clientAuth EKU contrary to CPS; remediation and action items continue
Actalis is the subject of a third-party Certificate Problem Report about publicly trusted TLS server certificates that were issued with both serverAuth and clientAuth EKUs, contrary to Actalis’s CP/CPS commitment to use only serverAuth from 2026-06-15. Actalis confirmed the inconsistency and said it affected about 260,000 certificates. The company reported that it made an emergency configuration change on 2026-08-02 to remove clientAuth from the affected issuance profiles, and that no further non-conforming certificates were issued after that point. Actalis also said all affected certificates had been revoked. The Full Incident Report was posted on 2026-08-14 and included the incident summary, impact, timeline, and affected-certificate attachments. Subsequent weekly updates said progress remained aligned with scheduled action items. On 2026-09-02, Actalis said the internal procedure governing quarterly self-audits was updated and that Action Item 2 was complete. The bug remains open and assigned, with further weekly updates promised in the thread.
- Actalis’s CP/CPS commitment to issue TLS subscriber certificates with only serverAuth took effect.
- Actalis received a third-party Certificate Problem Report about TLS server certificates containing both serverAuth and clientAuth EKUs.
- Actalis updated the affected certificate profiles to remove clientAuth from new issuance.
- Actalis confirmed that all affected certificates had been revoked.
- Actalis posted the Full Incident Report with the affected certificate corpus and timeline.
- Actalis updated the internal procedure governing quarterly self-audits.
- Actalis said Action Item 2 was complete.
- Staff representative — Actalis opened a preliminary incident report, confirmed the reported inconsistency, described the emergency configuration change, and said a Full Incident Report would follow by 2026-08-15.
- Staff representative — Actalis said all affected certificates had been revoked and that the full corpus and detailed timeline would be included in the Full Incident Report.
- Staff representative — Actalis said it was consolidating internal analysis, action items, and due dates, and would provide the Full Incident Report within the reporting deadline.
- Staff representative — Actalis posted the Full Incident Report, including the incident summary, impact, timeline, and affected-certificate attachments.
- Staff representative — Actalis said progress was aligned with scheduled action items and offered to provide further details.
- Staff representative — Actalis repeated that progress was aligned with scheduled action items and offered further details.
- Staff representative — Actalis said the internal procedure governing quarterly self-audits was updated and that Action Item 2 was complete.
- Staff representative — Actalis said progress was aligned with scheduled action items and offered further details.
- Staff representative — Actalis said progress was aligned with scheduled action items and offered further details.