← Asseco Data Systems S.A. cases
Bugzilla #1435770
Certificate Misissuance
Asseco DS / Certum: Non-BR-Compliant Issuance - Debian Weak Keys
RESOLVED
FIXED
Asseco Data Systems S.A.
AI Summary
The case involves Certum, a CA owned by Asseco Data Systems S.A., which issued two certificates containing Debian weak keys. These certificates were not revoked within the required 24-hour period after being reported, leading to a compliance issue. Certum acknowledged the problem, revoked the certificates, and conducted a thorough investigation, confirming no additional affected certificates were found. They have since implemented changes to their validation processes to prevent similar issues in the future.
Chronology
- Hanno Bock reported weak keys to Certum.
- Certum confirmed the need to revoke the certificates.
- Certum revoked the certificates.
- Certum deployed a new validation system.
- Certum submitted an incident report.
- Case marked as resolved.
Participants
Wayne Thayer
Arkadiusz Ławniczak
Hanno Bock
External References
Similar Local Cases
Asseco DS / Certum: Invalid value in SAN dNSName
Asseco DS / Certum: CAA Mis-Issuance on mix of wildcard and non-wildcard DNS names in SAN
Asseco DS / Certum: CAA mis-issuance on critical flag and unknown CAA tag
Asseco DS / Certum: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record
Asseco DS / Certum: EV certificate mis-issue
Asseco DS / Certum: S/MIME certificates with error in subjectAlternativeName
Asseco DS / Certum: EV Certificates issued with wrong Business Category
Asseco DS / Certum: Delayed revocation of EV certificates