← Asseco Data Systems S.A. cases
Bugzilla #1518560 Policy Compliance

Asseco DS / Certum: Use of forbidden subjectPublicKeyInfo algorithm

RESOLVED FIXED Asseco Data Systems S.A.
AI Summary

Asseco Data Systems S.A. was found to be issuing certificates that included the forbidden P-521 algorithm, violating Mozilla's Root Store Policy. The issue was reported in a Bugzilla case, prompting the CA to cease issuance of such certificates and to provide an incident report detailing the timeline and corrective actions taken. The CA has since implemented measures to ensure compliance with browser policies and has established a process for monitoring changes in requirements to prevent future occurrences.

Model: gpt-4o-mini Generated: 2026-06-13 17:57 UTC Confidence: 0.90
Chronology
  1. Bugzilla case created regarding the use of forbidden algorithm.
  2. CA blocked issuance of certificates with P-521 keys.
  3. CA completed documentation comparing technical requirements from browser policies.
Participants
Ryan Sleevi Wojciech Trapczyński
Similar Local Cases
#1717034 RESOLVED Policy Compliance Opened 2021-06-17 · Closed 2023-02-22 · 56% similar
Asseco DS / Certum: CPS does not refer to BR domain validation methods
#1815355 RESOLVED Policy Compliance Opened 2023-02-07 · Closed 2023-08-16 · 52% similar
Asseco DS / Certum: Cross-Signed non-EV-audited root with an EV-enabled root
#1391064 RESOLVED Policy Compliance Opened 2017-08-16 · Closed 2023-02-22 · 52% similar
SECOM: Non-BR-Compliant Certificate Issuance
#1935393 RESOLVED Policy Compliance Opened 2024-12-05 · Closed 2025-01-29 · 51% similar
Asseco DS / Certum: Failure to Update Policy Documents within 365 Days
#1700809 RESOLVED Policy Compliance Opened 2021-03-25 · Closed 2023-02-22 · 51% similar
Microsoft PKI Services: Failure to disclose Unconstrained Intermediate within 7 Days
#1719451 RESOLVED Policy Compliance Opened 2021-07-07 · Closed 2023-02-22 · 51% similar
PKIoverheid: KPN CPS Lists Forbidden Domain Validation Method 3.2.2.4.6
#1680378 RESOLVED Policy Compliance Opened 2020-12-02 · Closed 2023-02-22 · 50% similar
NetLock: Replacement of enduser certificates after the EVGL 1.7.4 self-audit
#1586787 RESOLVED Policy Compliance Opened 2019-10-07 · Closed 2023-02-22 · 50% similar
Actalis: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action