← Asseco Data Systems S.A. cases
Bugzilla #1451228
Certificate Misissuance
Asseco DS / Certum: EV certificate mis-issue
RESOLVED
FIXED
Asseco Data Systems S.A.
AI Summary
Asseco Data Systems S.A. faced an incident involving the mis-issuance of an Extended Validation (EV) certificate for the domain zegarownia.pl. The certificate incorrectly listed 'ZEGAROWNIA' as the organization name instead of the legally registered name '57 Concepts Sp. z o.o. Sp.k.'. This mis-issuance was attributed to a human error during the manual correction of the certification request. The certificate was revoked on April 10, 2018, and a subsequent review of other certificates revealed another similar issue, prompting a commitment to improve verification processes.
Chronology
- Initial report of mis-issued EV certificate.
- Certificate revoked due to mis-issuance.
- Incident report detailing the mis-issuance and corrective actions taken.
- Validation team retrained to prevent future issues.
Participants
Wojtek Babicz
Arkadiusz Ławniczak
W. Thayer
M. Purzyński
W. Trapczyński
External References
Similar Local Cases
Asseco DS / Certum: CAA Mis-Issuance on mix of wildcard and non-wildcard DNS names in SAN
Asseco DS / Certum: EV Certificates issued with wrong Business Category
Asseco DS / Certum: Non-BR-Compliant Issuance - Debian Weak Keys
Asseco DS / Certum: CAA mis-issuance on critical flag and unknown CAA tag
Asseco DS / Certum: S/MIME certificates with error in subjectAlternativeName
Asseco DS / Certum: Delayed revocation of EV certificates
Asseco DS / Certum: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record
Amazon Trust Services: No Space In Private Organization