Kathleen,

you do not see such subordinate in CCADB because it's a technically constrained subordinate, and there is no requirement (to date) to disclose technically constrained subordinates.

At any rate, I confirmed our issuance of such subordinate in my response to Gerv on 15/5/2017 when he asked ...

"Also, am I right in thinking that Actalis has recently cross-signedUniCredit?

   https://crt.sh/?id=47081615

"

I can easily find such subordinate in https://crt.sh/mozilla-disclosures#undisclosed. Actually there are two almost identical entries, alas, because of the doppelganger issue that we were not aware of until Sep 30, when we read the warning from Rob Stradling posted on m.d.s.p.

As I wrote in my report of Oct 2nd, today we are going to revoke the two doppelgangers.

Adriano



Il 03/10/2017 18:50, Kathleen Wilson via dev-security-policy ha scritto:
      Issuer:https://crt.sh/?caid=935
    Issuer O: Actalis S.p.A./03358520967
   Issuer CN: Actalis Authentication Root CA
Subject CN: UniCredit Subordinate External
    Serial #: 3e:5d:be:44:e7:51:5a:5a
       Certs:https://crt.sh/?id=47081615
              https://crt.sh/?id=147626411
    Revoked?: No
I am not finding these Actalis certs in the CCADB. Will include that in the 
Actalis bug as well.

By the way, I do not see them listed here:
https://crt.sh/mozilla-disclosures#undisclosed



Attachment: smime.p7s
Description: Firma crittografica S/MIME

_______________________________________________
dev-security-policy mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security-policy

Reply via email to