← Asseco Data Systems S.A. cases
Bugzilla #1433118
Ca Certificate Compliance
Asseco DS / Certum: certificate issued by Certum with compromised private key not revoked (windows10.microdone.cn)
RESOLVED
FIXED
Asseco Data Systems S.A.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
This case involves a certificate issued by Certum that was linked to a compromised private key. The issue was reported by Hanno Boeck, who possessed the private key and noted that the certificate had not been revoked despite notifying Certum. Following the report, Certum confirmed receipt and subsequently revoked the certificate. The CA is investigating why the initial report went unnoticed, attributing the oversight to an incorrect contact email on their website. The issue has been resolved with the certificate's revocation and updates to the contact information.
Chronology
- Certificate with compromised private key reported and not revoked.
- Certificate revoked by Certum after the report.
Thread Activity
- Hboeck representative — Reported a compromised private key associated with a Certum certificate.
- Fastly representative — Inquired about the revocation of the certificate.
- Assecods representative — Confirmed receipt of the report and began working on it.
- Assecods representative — Revoked the certificate.
- Assecods representative — Explained the investigation into the initial report's oversight.
- Assecods representative — Identified incorrect contact information as the cause of the oversight.
- Mozilla representative — Confirmed the issue was handled in another bug and added to OneCRL.
Participants
Community commenter
External References
Similar Local Cases
Asseco DS / Certum: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record
Asseco DS / Certum: CRL non-conformance with the TLS BRs
Asseco DS / Certum: Unallowed key usage for EC public key (Key Encipherment)
Asseco DS / Certum: Cross-Signed non-EV-audited root with an EV-enabled root
Asseco DS / Certum: S/MIME certificates with error in subjectAlternativeName
Asseco DS / Certum: Cross-certificate not included in 2024 S/MIME Audit statement
Asseco DS / Certum: CP/CPS, Revocation Requests Mechanism, Certificate Problem Report, CRL and OCSP disruption
Asseco DS / Certum: Organization Identifier and Country field discrepancies