← Asseco Data Systems S.A. cases
Bugzilla #1409766 Ca Certificate Compliance Self Reported Incident Certificate Misissuance

Asseco DS / Certum: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record

RESOLVED FIXED Asseco Data Systems S.A.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case involves Asseco Data Systems S.A. (Certum) disclosing a misissuance incident where a certificate was incorrectly issued for a domain due to improper CAA validation. The issue was reported by Quirin Scheitle on October 16, 2017, after which Certum acknowledged the problem and initiated an audit of all issued certificates. They confirmed that the misissue was caused by a flaw in their CAA validation process, particularly for domains with a 'www' prefix and CNAME records. Certum implemented corrective measures, including a new validation module, and revoked the misissued certificate on November 7, 2017. The incident was resolved with the deployment of the updated CAA validation system on September 11, 2018.

Model: gpt-4o-mini Generated: 2026-06-13 17:37 UTC Revised: 2026-06-16 18:01 UTC Confidence: 0.90 22 comments
Chronology
  1. Certificate issued incorrectly due to CAA misvalidation.
  2. Issue reported to Certum by Quirin Scheitle.
  3. Certum revoked the misissued certificate.
  4. Certum deployed a fixed CAA validation module.
Thread Activity
  1. Scheitle representative — Reported a misissuance incident involving a CAA record.
  2. Assecods representative — Confirmed issues with CAA checking and outlined a plan for improvements.
  3. Asseco Data Systems S.A. — Announced deployment of the automated CAA verification system.
  4. Fastly representative — Confirmed that remediation is complete and resolved the case.
Participants
Scheitle representative Mozilla representative Assecods representative Fastly representative Asseco Data Systems S.A. Community commenter
External References
Similar Local Cases
#1709392 RESOLVED Self Reported Incident Certificate Misissuance Opened 2021-05-04 · Closed 2023-02-22 · 100% similar
Asseco DS / Certum: Invalid stateOrProvinceName field (recurrent incident)
#1667684 RESOLVED Self Reported Incident Opened 2020-09-27 · Closed 2023-02-22 · 99% similar
Asseco DS / Certum: Failure to provide a preliminary report within 24 hours.
#1711208 RESOLVED Self Reported Incident Certificate Misissuance Opened 2021-05-14 · Closed 2023-02-22 · 99% similar
Asseco DS / Certum: Incorrect localityName
#1832093 RESOLVED Self Reported Incident Certificate Misissuance Opened 2023-05-09 · Closed 2023-06-02 · 99% similar
Asseco DS / Certum: Subordinate certificates with sequential serial number
#1639502 RESOLVED Self Reported Incident Opened 2020-05-20 · Closed 2023-02-22 · 98% similar
Asseco DS / Certum: Incorrect OCSP response encoding
#1917571 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2024-09-09 · Closed 2024-11-06 · 98% similar
Asseco DS / Certum: Organization Identifier and Country field discrepancies
#1409764 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-10-18 · Closed 2023-02-22 · 96% similar
Asseco DS / Certum: CAA mis-issuance on critical flag and unknown CAA tag
#1511459 RESOLVED Self Reported Incident Opened 2018-11-30 · Closed 2023-02-22 · 96% similar
Asseco DS / Certum: Corrupted certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action