← Actalis cases
Bugzilla #2060581 Ca Certificate Compliance Externally Reported Incident Certificate Misissuance Revocation Issue Problem Reporting Failure

Actalis third-party incident report: TLS server certificates issued with clientAuth EKU contrary to CPS; remediation and action items continue

ASSIGNED Actalis
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Actalis is the subject of a third-party Certificate Problem Report about publicly trusted TLS server certificates that were issued with both serverAuth and clientAuth EKUs, contrary to Actalis’s CP/CPS commitment to use only serverAuth from 2026-06-15. Actalis confirmed the inconsistency and said it affected about 260,000 certificates. The company reported that it made an emergency configuration change on 2026-08-02 to remove clientAuth from the affected issuance profiles, and that no further non-conforming certificates were issued after that point. Actalis also said all affected certificates had been revoked. The Full Incident Report was posted on 2026-08-14 and included the incident summary, impact, timeline, and affected-certificate attachments. Subsequent weekly updates said progress remained aligned with scheduled action items. On 2026-09-02, Actalis said the internal procedure governing quarterly self-audits was updated and that Action Item 2 was complete. The bug remains open and assigned, with further weekly updates promised in the thread.

Model: gpt-5.4-mini Generated: 2026-08-10 11:44 UTC Revised: 2026-09-20 07:00 UTC Confidence: 0.96 12 comments
Chronology
  1. Actalis’s CP/CPS commitment to issue TLS subscriber certificates with only serverAuth took effect.
  2. Actalis received a third-party Certificate Problem Report about TLS server certificates containing both serverAuth and clientAuth EKUs.
  3. Actalis updated the affected certificate profiles to remove clientAuth from new issuance.
  4. Actalis confirmed that all affected certificates had been revoked.
  5. Actalis posted the Full Incident Report with the affected certificate corpus and timeline.
  6. Actalis updated the internal procedure governing quarterly self-audits.
  7. Actalis said Action Item 2 was complete.
Thread Activity
  1. Staff representative — Actalis opened a preliminary incident report, confirmed the reported inconsistency, described the emergency configuration change, and said a Full Incident Report would follow by 2026-08-15.
  2. Staff representative — Actalis said all affected certificates had been revoked and that the full corpus and detailed timeline would be included in the Full Incident Report.
  3. Staff representative — Actalis said it was consolidating internal analysis, action items, and due dates, and would provide the Full Incident Report within the reporting deadline.
  4. Staff representative — Actalis posted the Full Incident Report, including the incident summary, impact, timeline, and affected-certificate attachments.
  5. Staff representative — Actalis said progress was aligned with scheduled action items and offered to provide further details.
  6. Staff representative — Actalis repeated that progress was aligned with scheduled action items and offered further details.
  7. Staff representative — Actalis said the internal procedure governing quarterly self-audits was updated and that Action Item 2 was complete.
  8. Staff representative — Actalis said progress was aligned with scheduled action items and offered further details.
  9. Staff representative — Actalis said progress was aligned with scheduled action items and offered further details.
Participants
Staff representative
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
#2049960 ASSIGNED Common Ca Database Ccadb Disclosure Issue Incident Externally Reported Incident Opened 2026-06-24 Still Open · 88% similar
Actalis: Undisclosed Subordinate CA Certificate
#2067210 ASSIGNED Self Reported Incident Certificate Misissuance Revocation Issue Delayed Revocation Opened 2026-08-27 Still Open · 81% similar
Actalis: Incorrect CRL Distribution Point in TLS Server Certificates
#2056934 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Repository Issue Opened 2026-07-22 Still Open · 80% similar
Actalis: failure to timely update CP/CPS for AgID SubCAs
#1943379 RESOLVED Certificate Misissuance Opened 2025-01-23 · Closed 2025-05-08 · 78% similar
Actalis: CRL with duplicate serial number in revokedCertificates
#2065634 ASSIGNED Ca Certificate Compliance Externally Reported Incident Certificate Misissuance Revocation Issue Opened 2026-08-21 Still Open · 73% similar
SSL.com: Invalid combinations of countryName, stateOrProvinceName, and localityName attributes
#2057915 ASSIGNED Ca Certificate Compliance Externally Reported Incident Certificate Misissuance Validation Issue Opened 2026-07-26 Still Open · 72% similar
SSL.com: Invalid Subject stateOrProvince Values
#2047843 RESOLVED Ca Certificate Compliance Problem Reporting Failure Revocation Issue Opened 2026-06-16 · Closed 2026-07-09 · 72% similar
Certigna: Pre-certificates not recognised by the OCSP responder
#2065895 ASSIGNED Ca Certificate Compliance Externally Reported Incident Certificate Misissuance Validation Issue Opened 2026-08-23 Still Open · 72% similar
GlobalSign: StateOrProvince and LocalityName value inconsistency

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

⚠

Confirm action