← Asseco Data Systems S.A. cases
Bugzilla #1511459
Certificate Problem Report
Asseco DS / Certum: Corrupted certificates
RESOLVED
FIXED
Asseco Data Systems S.A.
AI Summary
Asseco Data Systems S.A. reported an incident involving corrupted certificates due to issues with publishing CRLs. The problem was identified on November 10, 2018, when a notification from their monitoring system indicated issues with CRL publication. Affected certificates were revoked, and the incident was resolved by deploying a new version of the signing module on November 19, 2018. The CA confirmed that no expired CRLs were served during the incident, and OCSP responses were not impacted.
Chronology
- CA received notification of issues with publishing CRLs.
- CA confirmed corrupted signatures on some certificates.
- CA deployed a new version of the signing module.
Participants
Wojciech Trapczyński
Wayne Thayer
External References
Similar Local Cases
Asseco DS / Certum: Unallowed key usage for EC public key (Key Encipherment)
Asseco DS / Certum: Failure to revoke intermediate certificates within the BR time period
Asseco DS / Certum: Intermediate CA certificates not listed in audit report
Asseco DS / Certum: inconsistent disclosure of externally-operated intermediate
Asseco DS / Certum: Cross-Certificates subject encoding discrepancy
Asseco DS / Certum: Subordinate certificates with sequential serial number
Asseco DS / Certum: commonName not from subjectAltName entries
Asseco DS / Certum: Failure to revoke within 5 days