← Asseco Data Systems S.A. cases
Bugzilla #1435770 Ca Certificate Compliance

Asseco DS / Certum: Non-BR-Compliant Issuance - Debian Weak Keys

RESOLVED FIXED Asseco Data Systems S.A.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The case concerns two certificates issued by Certum that contained Debian weak keys. The issue was reported to Certum on 3-Feb-2018, and the CA stated that the BRs require such certificates to be revoked within 24 hours for key compromise, but they were not revoked as of 5-Feb-2018. Certum investigated the reported problem, confirmed that both affected certificates needed revocation, and revoked both certificates with revocation reason "Key Compromise" and invalidity date 03-Feb-2018. Certum also scanned its certificates database and reported that no additional active certificates with vulnerable keys were found. Certum identified the cause as incorrect calculation of the SHA1 fingerprint of the public key due to differences in how hashes were stored versus how CSR public key values were calculated, and it deployed a corrected weak-keys validation system on 8-Feb-2018 so that certification requests based on Debian weak keys would be rejected. The bug was marked RESOLVED with resolution FIXED after Certum provided an incident report and responded to questions about prevention; the reporter accepted a follow-up reminder about testing the full system.

Model: gpt-5.4-nano Generated: 2026-06-13 17:43 UTC Revised: 2026-06-16 18:03 UTC Confidence: 0.84 9 comments
Chronology
  1. Certum received a report requesting revocation of two certificates containing Debian weak keys.
  2. Certum had not yet revoked the reported certificates as of this date.
  3. Certum revoked the two affected certificates and scanned its certificate database for weak keys.
  4. Certum deployed an updated weak-keys validation system to reject certification requests based on Debian weak keys.
Thread Activity
  1. Fastly representative — Requested an incident report because two reported certificates with Debian weak keys had not been revoked as required within 24 hours.
  2. Fastly representative — Asked Certum to scan every active (non-expired, non-revoked) certificate issued for the reported problem.
  3. Assecods representative — Reported that Certum confirmed both certificates must be revoked, revoked them with reason "Key Compromise," scanned for additional weak keys, and stated it was treating the issue as a security incident.
  4. Asseco Data Systems S.A. — Stated the cause of incorrect weak-key validation was found, the fix was deployed on Feb 8, and a rescan found no other active vulnerable certificates.
  5. Mozilla representative — Changed QA contact per a referenced Bugzilla bug.
  6. Assecods representative — Provided the incident report including timeline, root cause (incorrect SHA1 fingerprint calculation), and steps to resolve and prevent recurrence.
  7. Fastly representative — Asked for more detail on how similar problems would be prevented and requested posting the incident report to the mozilla.dev.security.policy forum.
  8. Assecods representative — Explained that weak-keys verification tests were run, but the weak-keys database used for tests contained hashes in incorrect formats, leading to false positives.
  9. Fastly representative — Marked the bug resolved after a reminder about testing the full system even when unit tests pass.
Participants
Fastly representative Assecods representative Asseco Data Systems S.A. Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1451228 RESOLVED Ca Certificate Compliance Opened 2018-04-04 · Closed 2023-02-22 · 100% similar
Asseco DS / Certum: EV certificate mis-issue
#1420860 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-11-27 · Closed 2023-02-22 · 96% similar
Asseco DS / Certum: CAA Mis-Issuance on mix of wildcard and non-wildcard DNS names in SAN
#1409764 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-10-18 · Closed 2023-02-22 · 89% similar
Asseco DS / Certum: CAA mis-issuance on critical flag and unknown CAA tag
#1600301 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-11-29 · Closed 2023-02-22 · 89% similar
Asseco DS / Certum: EV Certificates issued with wrong Business Category
#1823040 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2023-03-17 · Closed 2023-05-19 · 88% similar
Asseco DS / Certum: Cross-certificate with wrong policy identifier
#1409766 RESOLVED Ca Certificate Compliance Self Reported Incident Certificate Misissuance Opened 2017-10-18 · Closed 2023-02-22 · 85% similar
Asseco DS / Certum: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record
#1600158 RESOLVED Ca Certificate Compliance Delayed Revocation Opened 2019-11-28 · Closed 2023-02-22 · 77% similar
Asseco DS / Certum: Failure to revoke intermediate certificates within the BR time period
#1909203 RESOLVED Ca Certificate Compliance Incident Opened 2024-07-22 · Closed 2025-05-13 · 72% similar
Asseco DS / Certum: CP/CPS, Revocation Requests Mechanism, Certificate Problem Report, CRL and OCSP disruption

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action