Asseco Data Systems / Certum: Use of forbidden subjectPublicKeyInfo algorithm (P-521)
This case concerns certificates issued by Asseco Data Systems S.A. / Certum that used a forbidden subjectPublicKeyInfo algorithm, specifically P-521 keys. The issue was reported in the mozilla.dev.security.policy forum and referenced in Bugzilla bug 1518560, with Mozilla requesting an incident report from the CA. In response, the CA stated it had stopped issuing certificates that include P-521 keys and provided an incident timeline and details of the problematic certificate(s). The CA explained that after Mozilla Root Store Policy v2.4 (released Feb 28, 2017), it did not change allowed public key algorithms accordingly, and that the team responsible for policy inspection did not report the change to the product manager. As remediation, the CA described team monitoring of CA/B Forum and browser policy changes, regular meetings, and a process to implement and then review compliance after changes. The CA also stated it created documentation comparing technical requirements from browser policies (including CA/Browser Forum BR) and reviewed operational practices, reporting no non-conformity; the bug was resolved as FIXED.
- Mozilla Root Store Policy v2.4 was released.
- A certificate including P-521 keys was issued.
- Bugzilla bug 1518560 was created after the issue was reported in mozilla.dev.security.policy.
- The CA blocked issuing certificates that include P-521 keys.
- The CA reported completion of documentation comparing technical requirements and stated operational practices were reviewed.
- Community commenter — Requested an incident report and listed the reported problem as P-521 in certificates, linking to the mozilla.dev.security.policy discussion.
- Asseco Data Systems S.A. — Acknowledged that an incident report would be provided soon.
- Community commenter — Asked for weekly updates per Mozilla guidance.
- Asseco Data Systems S.A. — Provided an incident report including awareness, timeline, statement that issuing with P-521 keys was stopped, and remediation steps.
- Community commenter — Asked for more detail on processes and procedures to ensure future compliance.
- Asseco Data Systems S.A. — Described a monitoring and implementation process for policy changes and an additional action to review browser policies and draw up technical differences.
- Fastly representative — Requested an update when the browser-policy comparison documentation work was completed.
- Asseco Data Systems S.A. — Reported that documentation was created to compare technical requirements and that operational practices were reviewed with no non-conformity found.