Asseco Data Systems / Certum: Corrupted certificates (CRL signature issue)
Asseco Data Systems S.A. (Certum) reported an incident after its internal monitoring system notified it of problems publishing CRLs. The CA determined that one of about 50 CRLs had a corrupted digital signature value and that, within a short period, over 30,000 certificates had been added to that CRL. The CA confirmed that its signing module could not correctly sign CRLs larger than 1 MB, and that this led to corrupted signatures on some issued certificates; it also noted that multiple signing modules were used in parallel, so the issue did not affect all certificates issued at the time. In response, the CA disabled automatic publication of the affected CRL, turned off the signing module producing corrupted signatures, revoked the affected certificates, and deployed additional external signature verification and a new signing module version that correctly handled large CRLs. The CA stated that it was serving one CRL with a corrupted signature between 2018-11-10 01:05 and 2018-11-14 07:35, and that OCSP was not impacted. Mozilla participants later discussed the incident, and the thread was resolved as remediation being complete and discussion ending. The bug is marked RESOLVED with resolution FIXED.
- Internal monitoring notified the CA of issues publishing CRLs, leading to investigation of corrupted CRL signatures.
- The CA established that one CRL had a corrupted digital signature and that it had grown much larger than others.
- The CA confirmed the signing module could not correctly sign CRLs larger than 1 MB and began remediation.
- The CA disabled automatic publication of the affected CRL after verifying other CRLs had correct signatures.
- The CA inspected the system and identified certificate signature corruption tied to a specific signing module.
- The CA deployed external signature verification and a new signing module version that correctly handled large CRLs.
- Asseco Data Systems S.A. — Opened the incident report describing the CA’s discovery, timeline, causes, and remediation steps for corrupted CRL signatures and affected certificates.
- Fastly representative — Asked questions about the sudden revocations, whether any expired/BR-violating CRLs were served, OCSP impact, reporting delay, and requested posting to the mozilla.dev.security.policy mailing list.
- Asseco Data Systems S.A. — Answered the questions, stating there was no key compromise, no expired CRLs were served, OCSP was not impacted, and explaining the reporting delay; also confirmed posting to the mailing list.
- Asseco Data Systems S.A. — Corrected a typo in the reported date range in a prior answer.
- Fastly representative — Pointed to further discussion of the issue on the mozilla.dev.security.policy mailing list.
- Fastly representative — Reported that the incident was being resolved because remediation appeared complete and discussion had ended.