← Asseco Data Systems S.A. cases
Bugzilla #1451228 Ca Certificate Compliance

Asseco DS / Certum: EV certificate mis-issue

RESOLVED FIXED Asseco Data Systems S.A.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The case reports an EV (extended validation) certificate mis-issuance by Certum (Asseco/Certum) for domain zegarownia.pl. The EV certificate’s “Green bar”/subject information contained “ZEGAROWNIA” as the organization name, which the reporter stated was not the legally registered company name; the legal company name was given as “57 Concepts Sp. z o.o. Sp.k.” Mozilla asked Certum to review the referenced certificate and either explain how it was properly issued or file an incident report if it was misissued. Certum responded that the issue was an isolated incident caused by human error when manually correcting the certification request, specifically placing trademark “Zegarownia” in the Organization Name field while the legal company name was placed in the Organizational Unit Name field. Certum revoked the misissued EV certificate on April 10, 2018, and later provided an incident report describing the investigation, including that they found another EV certificate with an incomplete owner name in organizationName and revoked both certificates. Certum stated that vetting procedures were reviewed and the validation team was re-trained on CA/Browser Forum requirements for SSL and EV SSL certificates. The bug is resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 17:47 UTC Revised: 2026-06-16 18:03 UTC Confidence: 0.90 8 comments
Chronology
  1. Certum issued an EV certificate for zegarownia.pl with subject/organization naming that did not match the legally registered company name as reported.
  2. Certum revoked the misissued EV certificate 919DCADE40713F715E560005E868BAB18142DD97.
  3. Certum revoked a second EV certificate identified during review (022099F0DD4F0B16917884F49A61F6F9927EEE95).
  4. Certum reported that vetting procedures were reviewed and the validation team was re-trained on SSL/EV SSL requirements.
Thread Activity
  1. Trustnet representative — Reported that Certum mis-issued an EV certificate for zegarownia.pl because the EV “Green bar”/subject organization name used “ZEGAROWNIA” instead of the legal company name “57 Concepts Sp. z o.o. Sp.k.”
  2. Fastly representative — Asked Arkadiusz to review the referenced certificate and either confirm proper issuance or file an incident report if it was misissued.
  3. Community commenter — Questioned whether Certum would issue an EV certificate with any string requested.
  4. Asseco Data Systems S.A. — Stated that Certum verified the trademark “Zegarownia” and applicant identity, said the incident was human error in field placement, and reported revocation of the certificate on April 10, 2018.
  5. Fastly representative — Requested a full incident report and asked whether Certum looked for additional certificates with the same problem and what prevention steps would be taken.
  6. Assecods representative — Provided an incident report describing the investigation, identified a second EV certificate with an incomplete organizationName, and stated both certificates were revoked; also described the cause as human error during manual correction.
  7. Fastly representative — Asked what steps had been or would be taken to prevent the issues from happening again.
  8. Assecods representative — Reported that vetting procedures were reviewed and the validation team was re-trained on CA/Browser Forum requirements for SSL and EV SSL certificates.
Participants
Trustnet representative Fastly representative Community commenter Asseco Data Systems S.A. Assecods representative
Similar Local Cases
#1435770 RESOLVED Ca Certificate Compliance Opened 2018-02-05 · Closed 2023-02-22 · 100% similar
Asseco DS / Certum: Non-BR-Compliant Issuance - Debian Weak Keys
#1420860 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-11-27 · Closed 2023-02-22 · 96% similar
Asseco DS / Certum: CAA Mis-Issuance on mix of wildcard and non-wildcard DNS names in SAN
#1409764 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-10-18 · Closed 2023-02-22 · 89% similar
Asseco DS / Certum: CAA mis-issuance on critical flag and unknown CAA tag
#1600301 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-11-29 · Closed 2023-02-22 · 89% similar
Asseco DS / Certum: EV Certificates issued with wrong Business Category
#1823040 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2023-03-17 · Closed 2023-05-19 · 87% similar
Asseco DS / Certum: Cross-certificate with wrong policy identifier
#1409766 RESOLVED Ca Certificate Compliance Self Reported Incident Certificate Misissuance Opened 2017-10-18 · Closed 2023-02-22 · 85% similar
Asseco DS / Certum: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record
#1600158 RESOLVED Ca Certificate Compliance Delayed Revocation Opened 2019-11-28 · Closed 2023-02-22 · 74% similar
Asseco DS / Certum: Failure to revoke intermediate certificates within the BR time period
#2002281 RESOLVED Ca Certificate Compliance Opened 2025-11-25 · Closed 2025-12-11 · 70% similar
Asseco DS / Certum: Irregularities in Xinchacha/Xcc Brand SSL Certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action