← Asseco Data Systems S.A. cases
Bugzilla #1518560 Certificate Misissuance

Asseco Data Systems / Certum: Use of forbidden subjectPublicKeyInfo algorithm (P-521)

RESOLVED FIXED Asseco Data Systems S.A.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns certificates issued by Asseco Data Systems S.A. / Certum that used a forbidden subjectPublicKeyInfo algorithm, specifically P-521 keys. The issue was reported in the mozilla.dev.security.policy forum and referenced in Bugzilla bug 1518560, with Mozilla requesting an incident report from the CA. In response, the CA stated it had stopped issuing certificates that include P-521 keys and provided an incident timeline and details of the problematic certificate(s). The CA explained that after Mozilla Root Store Policy v2.4 (released Feb 28, 2017), it did not change allowed public key algorithms accordingly, and that the team responsible for policy inspection did not report the change to the product manager. As remediation, the CA described team monitoring of CA/B Forum and browser policy changes, regular meetings, and a process to implement and then review compliance after changes. The CA also stated it created documentation comparing technical requirements from browser policies (including CA/Browser Forum BR) and reviewed operational practices, reporting no non-conformity; the bug was resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 17:57 UTC Revised: 2026-06-16 18:04 UTC Confidence: 0.86 10 comments
Chronology
  1. Mozilla Root Store Policy v2.4 was released.
  2. A certificate including P-521 keys was issued.
  3. Bugzilla bug 1518560 was created after the issue was reported in mozilla.dev.security.policy.
  4. The CA blocked issuing certificates that include P-521 keys.
  5. The CA reported completion of documentation comparing technical requirements and stated operational practices were reviewed.
Thread Activity
  1. Community commenter — Requested an incident report and listed the reported problem as P-521 in certificates, linking to the mozilla.dev.security.policy discussion.
  2. Asseco Data Systems S.A. — Acknowledged that an incident report would be provided soon.
  3. Community commenter — Asked for weekly updates per Mozilla guidance.
  4. Asseco Data Systems S.A. — Provided an incident report including awareness, timeline, statement that issuing with P-521 keys was stopped, and remediation steps.
  5. Community commenter — Asked for more detail on processes and procedures to ensure future compliance.
  6. Asseco Data Systems S.A. — Described a monitoring and implementation process for policy changes and an additional action to review browser policies and draw up technical differences.
  7. Fastly representative — Requested an update when the browser-policy comparison documentation work was completed.
  8. Asseco Data Systems S.A. — Reported that documentation was created to compare technical requirements and that operational practices were reviewed with no non-conformity found.
Participants
Community commenter Asseco Data Systems S.A. Fastly representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1524878 RESOLVED Certificate Misissuance Duplicate Or Superseded Opened 2019-02-03 · Closed 2023-02-22 · 79% similar
Asseco DS / Certum: IP in dnsName
#1579299 RESOLVED Repository Issue Certificate Misissuance Opened 2019-09-06 · Closed 2023-02-22 · 79% similar
Asseco DS / Certum: non-audited intermediate certificate
#1710206 RESOLVED Externally Reported Incident Certificate Misissuance Opened 2021-05-08 · Closed 2022-11-14 · 79% similar
Asseco DS / Certum: Incorrect localityName
#1518555 RESOLVED Certificate Misissuance Opened 2019-01-08 · Closed 2023-02-22 · 63% similar
DigiCert: Use of forbidden subjectPublicKeyInfo algorithm
#1532429 RESOLVED Certificate Misissuance Self Reported Incident Opened 2019-03-04 · Closed 2023-02-22 · 62% similar
CFCA: Invalid TLD in SAN
#1645708 RESOLVED Certificate Misissuance Opened 2020-06-14 · Closed 2023-02-22 · 61% similar
QuoVadis: EV serialNumber with "none"
#1649947 RESOLVED Certificate Misissuance Opened 2020-07-02 · Closed 2023-02-22 · 61% similar
Microsec: Incorrect OCSP Delegated Responder Certificate
#1705647 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-04-16 · Closed 2023-02-22 · 61% similar
KIR S.A.: Invalid organizationName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action