← Asseco Data Systems S.A. cases
Bugzilla #1433118 Ca Certificate Compliance

Asseco DS / Certum: certificate issued by Certum with compromised private key not revoked (windows10.microdone.cn)

RESOLVED FIXED Asseco Data Systems S.A.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case involves a certificate issued by Certum that was linked to a compromised private key. The issue was reported by Hanno Boeck, who possessed the private key and noted that the certificate had not been revoked despite notifying Certum. Following the report, Certum confirmed receipt and subsequently revoked the certificate. The CA is investigating why the initial report went unnoticed, attributing the oversight to an incorrect contact email on their website. The issue has been resolved with the certificate's revocation and updates to the contact information.

Model: gpt-4o-mini Generated: 2026-06-13 17:43 UTC Revised: 2026-06-16 18:02 UTC Confidence: 0.90 16 comments
Chronology
  1. Certificate with compromised private key reported and not revoked.
  2. Certificate revoked by Certum after the report.
Thread Activity
  1. Hboeck representative — Reported a compromised private key associated with a Certum certificate.
  2. Fastly representative — Inquired about the revocation of the certificate.
  3. Assecods representative — Confirmed receipt of the report and began working on it.
  4. Assecods representative — Revoked the certificate.
  5. Assecods representative — Explained the investigation into the initial report's oversight.
  6. Assecods representative — Identified incorrect contact information as the cause of the oversight.
  7. Mozilla representative — Confirmed the issue was handled in another bug and added to OneCRL.
Participants
Community commenter
External References
Similar Local Cases
#1409766 RESOLVED Ca Certificate Compliance Self Reported Incident Certificate Misissuance Opened 2017-10-18 · Closed 2023-02-22 · 80% similar
Asseco DS / Certum: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record
#1888689 RESOLVED Ca Certificate Compliance Incident Opened 2024-03-29 · Closed 2024-10-02 · 80% similar
Asseco DS / Certum: CRL non-conformance with the TLS BRs
#1495518 RESOLVED Ca Certificate Compliance Opened 2018-10-01 · Closed 2023-02-22 · 79% similar
Asseco DS / Certum: Unallowed key usage for EC public key (Key Encipherment)
#1815355 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2023-02-07 · Closed 2023-08-16 · 79% similar
Asseco DS / Certum: Cross-Signed non-EV-audited root with an EV-enabled root
#1879845 RESOLVED Ca Certificate Compliance Opened 2024-02-12 · Closed 2024-10-02 · 79% similar
Asseco DS / Certum: S/MIME certificates with error in subjectAlternativeName
#1904494 RESOLVED Ca Certificate Compliance Ca Documents Audit Document Remediation Tracking Opened 2024-06-25 · Closed 2024-09-04 · 79% similar
Asseco DS / Certum: Cross-certificate not included in 2024 S/MIME Audit statement
#1909203 RESOLVED Ca Certificate Compliance Incident Opened 2024-07-22 · Closed 2025-05-13 · 79% similar
Asseco DS / Certum: CP/CPS, Revocation Requests Mechanism, Certificate Problem Report, CRL and OCSP disruption
#1917571 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2024-09-09 · Closed 2024-11-06 · 78% similar
Asseco DS / Certum: Organization Identifier and Country field discrepancies

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action