Actalis third-party incident report: TLS server certificates issued with clientAuth EKU contrary to CPS
Actalis reported a third-party Certificate Problem Report about publicly trusted TLS Server Certificates that included both serverAuth and clientAuth EKUs after its CPS said that, starting no later than 2026-06-15, the EKU would contain only serverAuth. Actalis said its preliminary investigation confirmed the inconsistency and identified about 260,000 affected certificates. It also stated that the presence of clientAuth in these TLS server certificates was not prohibited by the CA/B Forum TLS Baseline Requirements or applicable root store policy, but it did conflict with Actalis’s own CP/CPS commitment. Actalis said it made an emergency configuration change on 2026-08-02 to remove clientAuth from the affected profiles and that no further non-conforming certificates were issued after that point. On 2026-08-06, Actalis confirmed that all affected certificates had been revoked and said the full corpus and detailed timeline would be included in the Full Incident Report.
- Actalis received a third-party Certificate Problem Report about TLS server certificates containing both serverAuth and clientAuth EKUs after the CPS cutoff date.
- Actalis changed the affected TLS certificate profile configuration to remove clientAuth from new issuance.
- Actalis confirmed that all affected certificates had been revoked.
- Staff representative — Actalis opened a preliminary incident report, confirmed the reported inconsistency, described the emergency configuration change, and said a Full Incident Report would follow by 2026-08-15.
- Staff representative — Actalis said all affected certificates had been revoked and that the full corpus and detailed timeline would be included in the Full Incident Report.