← Actalis cases
Bugzilla #2060581 Ca Certificate Compliance Externally Reported Incident Certificate Misissuance Revocation Issue Problem Reporting Failure

Actalis third-party incident report: TLS server certificates issued with clientAuth EKU contrary to CPS

ASSIGNED Actalis
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Actalis reported a third-party Certificate Problem Report about publicly trusted TLS Server Certificates that included both serverAuth and clientAuth EKUs after its CPS said that, starting no later than 2026-06-15, the EKU would contain only serverAuth. Actalis said its preliminary investigation confirmed the inconsistency and identified about 260,000 affected certificates. It also stated that the presence of clientAuth in these TLS server certificates was not prohibited by the CA/B Forum TLS Baseline Requirements or applicable root store policy, but it did conflict with Actalis’s own CP/CPS commitment. Actalis said it made an emergency configuration change on 2026-08-02 to remove clientAuth from the affected profiles and that no further non-conforming certificates were issued after that point. On 2026-08-06, Actalis confirmed that all affected certificates had been revoked and said the full corpus and detailed timeline would be included in the Full Incident Report.

Model: gpt-5.4-mini Generated: 2026-08-10 11:44 UTC Confidence: 0.96 2 comments
Chronology
  1. Actalis received a third-party Certificate Problem Report about TLS server certificates containing both serverAuth and clientAuth EKUs after the CPS cutoff date.
  2. Actalis changed the affected TLS certificate profile configuration to remove clientAuth from new issuance.
  3. Actalis confirmed that all affected certificates had been revoked.
Thread Activity
  1. Staff representative — Actalis opened a preliminary incident report, confirmed the reported inconsistency, described the emergency configuration change, and said a Full Incident Report would follow by 2026-08-15.
  2. Staff representative — Actalis said all affected certificates had been revoked and that the full corpus and detailed timeline would be included in the Full Incident Report.
Participants
Staff representative
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
#1943379 RESOLVED Certificate Misissuance Opened 2025-01-23 · Closed 2025-05-08 · 77% similar
Actalis: CRL with duplicate serial number in revokedCertificates
#2057915 ASSIGNED Ca Certificate Compliance Externally Reported Incident Certificate Misissuance Validation Issue Opened 2026-07-26 Still Open · 71% similar
SSL.com: Invalid Subject stateOrProvince Values
#2032485 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2026-04-16 · Closed 2026-05-04 · 71% similar
DigiCert: Misissuance detected by PKIMetal
#2056882 ASSIGNED Externally Reported Incident Certificate Misissuance Closure Request Opened By Subscriber Or Relying Party Opened 2026-07-22 Still Open · 70% similar
D-Trust: EV Subordinate CA missing required cabfOrganizationIdentifier extension
#2047843 RESOLVED Ca Certificate Compliance Problem Reporting Failure Revocation Issue Opened 2026-06-16 · Closed 2026-07-09 · 70% similar
Certigna: Pre-certificates not recognised by the OCSP responder
#1910451 RESOLVED Certificate Misissuance Revocation Issue Opened 2024-07-29 · Closed 2024-08-21 · 70% similar
Sectigo: Missing character in subject:organizationName attribute value
#1705647 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-04-16 · Closed 2023-02-22 · 70% similar
KIR S.A.: Invalid organizationName
#1705657 RESOLVED Ca Certificate Compliance Revocation Issue Opened 2021-04-16 · Closed 2023-02-22 · 70% similar
KIR S.A.: Many certificates with OCSP Unknown

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action