← Asseco Data Systems S.A. cases
Bugzilla #1495518
Certificate Problem Report
Asseco DS / Certum: Unallowed key usage for EC public key (Key Encipherment)
RESOLVED
FIXED
Asseco Data Systems S.A.
AI Summary
Asseco Data Systems S.A. faced an issue with certificates issued by their subordinate CA, Yandex, which had unallowed key usage for EC public keys. An incident report was requested and subsequently provided, detailing the timeline of events and corrective actions taken. The CA identified the root cause as a software misconfiguration that allowed incorrect profiles for certificate requests. Remediation steps included software fixes and the implementation of pre-issuance linting to prevent future misissuance. The case has been resolved with all affected certificates revoked.
Chronology
- Bug created by Wayne Thayer regarding unallowed key usage.
- Certum acknowledged the issue and began preparing a fix.
- Fix deployed on production and affected customers informed.
- Fully automatic pre-issuance linting deployed.
Participants
Wayne Thayer
Wojciech Trapczyński
External References
Similar Local Cases
Asseco DS / Certum: Intermediate CA certificates not listed in audit report
Asseco DS / Certum: Failure to revoke intermediate certificates within the BR time period
Asseco DS / Certum: Corrupted certificates
Asseco DS / Certum: inconsistent disclosure of externally-operated intermediate
Asseco DS / Certum: commonName not from subjectAltName entries
Asseco DS / Certum: Invalid dnsNames
Asseco DS / Certum: certificate issued by Certum with compromised private key not revoked (windows10.microdone.cn)
Asseco DS / Certum: IP in dnsName