← Asseco Data Systems S.A. cases
Bugzilla #1495518
Ca Certificate Compliance
Asseco DS / Certum: Unallowed key usage for EC public key (Key Encipherment)
RESOLVED
FIXED
Asseco Data Systems S.A.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
Asseco Data Systems S.A. (Certum) reported a compliance issue involving unallowed key usage for certificates issued with EC public keys. The problem was identified through a Bugzilla report created by Wayne Thayer on October 1, 2018. Certum acknowledged the issue, provided a detailed incident report, and outlined corrective actions taken, including revocation of affected certificates and software fixes to prevent future occurrences. The CA implemented pre-issuance linting to enhance detection of misissuance. The case has been resolved with all necessary actions completed.
Chronology
- Bugzilla bug 1495518 created regarding unallowed key usage.
- Certum deployed fully automatic pre-issuance linting for SSL certificates.
Thread Activity
- Fastly representative — Reported the issue regarding unallowed key usage for EC public keys.
- Asseco Data Systems S.A. — Provided a detailed incident report addressing the compliance issue.
- Fastly representative — Confirmed that all questions have been answered and remediation is complete.
Participants
Fastly representative
Asseco Data Systems S.A.
External References
Similar Local Cases
Asseco DS / Certum: S/MIME certificates with error in subjectAlternativeName
Asseco DS / Certum: Cross-Signed non-EV-audited root with an EV-enabled root
Asseco DS / Certum: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record
Asseco DS / Certum: CRL non-conformance with the TLS BRs
Asseco DS / Certum: Cross-certificate not included in 2024 S/MIME Audit statement
Asseco DS / Certum: CP/CPS, Revocation Requests Mechanism, Certificate Problem Report, CRL and OCSP disruption
Asseco DS / Certum: Organization Identifier and Country field discrepancies
Asseco DS / Certum: certificate issued by Certum with compromised private key not revoked (windows10.microdone.cn)