← Asseco Data Systems S.A. cases
Bugzilla #1511459 Self Reported Incident

Asseco Data Systems / Certum: Corrupted certificates (CRL signature issue)

RESOLVED FIXED Asseco Data Systems S.A.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Asseco Data Systems S.A. (Certum) reported an incident after its internal monitoring system notified it of problems publishing CRLs. The CA determined that one of about 50 CRLs had a corrupted digital signature value and that, within a short period, over 30,000 certificates had been added to that CRL. The CA confirmed that its signing module could not correctly sign CRLs larger than 1 MB, and that this led to corrupted signatures on some issued certificates; it also noted that multiple signing modules were used in parallel, so the issue did not affect all certificates issued at the time. In response, the CA disabled automatic publication of the affected CRL, turned off the signing module producing corrupted signatures, revoked the affected certificates, and deployed additional external signature verification and a new signing module version that correctly handled large CRLs. The CA stated that it was serving one CRL with a corrupted signature between 2018-11-10 01:05 and 2018-11-14 07:35, and that OCSP was not impacted. Mozilla participants later discussed the incident, and the thread was resolved as remediation being complete and discussion ending. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 17:57 UTC Revised: 2026-06-16 18:04 UTC Confidence: 0.90 6 comments
Chronology
  1. Internal monitoring notified the CA of issues publishing CRLs, leading to investigation of corrupted CRL signatures.
  2. The CA established that one CRL had a corrupted digital signature and that it had grown much larger than others.
  3. The CA confirmed the signing module could not correctly sign CRLs larger than 1 MB and began remediation.
  4. The CA disabled automatic publication of the affected CRL after verifying other CRLs had correct signatures.
  5. The CA inspected the system and identified certificate signature corruption tied to a specific signing module.
  6. The CA deployed external signature verification and a new signing module version that correctly handled large CRLs.
Thread Activity
  1. Asseco Data Systems S.A. — Opened the incident report describing the CA’s discovery, timeline, causes, and remediation steps for corrupted CRL signatures and affected certificates.
  2. Fastly representative — Asked questions about the sudden revocations, whether any expired/BR-violating CRLs were served, OCSP impact, reporting delay, and requested posting to the mozilla.dev.security.policy mailing list.
  3. Asseco Data Systems S.A. — Answered the questions, stating there was no key compromise, no expired CRLs were served, OCSP was not impacted, and explaining the reporting delay; also confirmed posting to the mailing list.
  4. Asseco Data Systems S.A. — Corrected a typo in the reported date range in a prior answer.
  5. Fastly representative — Pointed to further discussion of the issue on the mozilla.dev.security.policy mailing list.
  6. Fastly representative — Reported that the incident was being resolved because remediation appeared complete and discussion had ended.
Participants
Asseco Data Systems S.A. Fastly representative
Similar Local Cases
#1409766 RESOLVED Ca Certificate Compliance Self Reported Incident Certificate Misissuance Opened 2017-10-18 · Closed 2023-02-22 · 96% similar
Asseco DS / Certum: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record
#1832093 RESOLVED Self Reported Incident Certificate Misissuance Opened 2023-05-09 · Closed 2023-06-02 · 88% similar
Asseco DS / Certum: Subordinate certificates with sequential serial number
#1639502 RESOLVED Self Reported Incident Opened 2020-05-20 · Closed 2023-02-22 · 87% similar
Asseco DS / Certum: Incorrect OCSP response encoding
#1709392 RESOLVED Self Reported Incident Certificate Misissuance Opened 2021-05-04 · Closed 2023-02-22 · 87% similar
Asseco DS / Certum: Invalid stateOrProvinceName field (recurrent incident)
#1667684 RESOLVED Self Reported Incident Opened 2020-09-27 · Closed 2023-02-22 · 86% similar
Asseco DS / Certum: Failure to provide a preliminary report within 24 hours.
#2021685 RESOLVED Self Reported Incident Opened 2026-03-07 · Closed 2026-04-30 · 81% similar
Asseco DS / Certum: Finding in Routine WebTrust Audit – S/MIME certificates issued with mailbox validation older than 30 days
#1611458 RESOLVED Self Reported Incident Opened 2020-01-24 · Closed 2023-02-22 · 79% similar
Asseco DS / Certum: Invalid value in SAN dNSName
#1711208 RESOLVED Self Reported Incident Certificate Misissuance Opened 2021-05-14 · Closed 2023-02-22 · 79% similar
Asseco DS / Certum: Incorrect localityName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action