← Actalis cases
Bugzilla #1405817
Certificate Misissuance
Actalis: Certs issued with same issuer and serial number
RESOLVED
FIXED
Actalis
AI Summary
Actalis issued intermediate certificates with the same issuer and serial number, violating the serial number uniqueness requirement of the BRs and RFC5280. The affected SubCA certificate was scheduled for revocation on October 4, 2017. Remedial actions included updates to their post-processing software and staff training to prevent recurrence. The issue was resolved with the completion of all action items, including the decommissioning of the legacy software.
Chronology
- Initial incident report provided; affected SubCA certificate scheduled for revocation.
- Update on remedial actions; SubCA certificate revoked as scheduled.
- Confirmation that all action items completed and issue closed.
Participants
Kathleen Wilson
Adriano Santoni
Gervase Markham
W. Thayer
External References
Similar Local Cases
Disig: Non-BR-Compliant Certificate Issuance
Camerfirma: Certs issued with same issuer and serial number
Actalis: Insufficient serial number entropy
SwissSign: Two certs issued with same issuer and serial number
Let's Encrypt: certs issued contrary to CPS due to incomplete blocklist
WoSign issued SHA-1 SSL certs and backdated the issuance date on SSL certificates
Microsec: Non-BR-Compliant Certificate Issuance
DigiCert / Inteso San Paulo: Double dot characters