← Asseco Data Systems S.A. cases
Bugzilla #1550575 Certificate Misissuance

Asseco DS / Certum: commonName not from subjectAltName entries

RESOLVED FIXED Asseco Data Systems S.A.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case is an incident report from Asseco Data Systems S.A. / Certum describing two SSL certificate misissuances where the certificate Common Name value was not taken from the Subject Alternative Name entries. The CA said it became aware of the issue during its regular crt.sh lint tools review on May 8, 2019, and identified that the first and second problematic certificates were issued on May 6 and May 7, 2019. The CA stated the mistake was caused by a software bug in its certificate data correction process: when an inspector changed request data (e.g., Locality Name or Organizational Unit Name), the Common Name value was removed from Subject Alternative Name. The CA reported that the problematic certificates were revoked, blocked further issuance possibilities by disallowing a correction workaround, and fixed the software with a plan to deploy it at the end of May 2019. To prevent recurrence, the CA added a test scenario to verify that the Common Name value is present in Subject Alternative Name and developed pre-issuance linting, which it later deployed fully automatically in production on July 17, 2019. A Fastly participant indicated that remediation appeared complete, and the bug is resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 18:12 UTC Revised: 2026-06-16 18:05 UTC Confidence: 0.86 10 comments
Chronology
  1. First SSL certificate with Common Name not from Subject Alternative Name was issued.
  2. Second SSL certificate with Common Name not from Subject Alternative Name was issued.
  3. CA became aware of the two misissuances and identified the cause.
  4. CA deployed fully automatic pre-issuance linting for SSL certificates in production.
Thread Activity
  1. Asseco Data Systems S.A. — Opened an incident report describing how the CA discovered two misissuances, the timeline, the cause (software bug), revocation of the certificates, and remediation steps including software fix and pre-issuance linting.
  2. Assecods representative — Confirmed the software fix was completed and the bug no longer appeared; pre-issuance linting development was ongoing.
  3. Community commenter — Asked whether the estimated timeline was 30-June-2019.
  4. Asseco Data Systems S.A. — Explained the production installation was delayed due to integration with a larger update, with test deployment planned and periodic verification continuing until implementation.
  5. Community commenter — Requested an update on remediation progress and specific dates.
  6. Asseco Data Systems S.A. — Confirmed the plan and stated he would keep the participant informed.
  7. Asseco Data Systems S.A. — Apologized for not sharing test results, confirmed testing was successful, and stated production deployment would occur before July 27.
  8. Asseco Data Systems S.A. — Reported that fully automatic pre-issuance linting was deployed in production on July 17, 2019.
  9. Fastly representative — Indicated it appeared all questions were answered and remediation was complete.
Participants
Asseco Data Systems S.A. Assecods representative Community commenter Fastly representative
Similar Local Cases
#1600301 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-11-29 · Closed 2023-02-22 · 100% similar
Asseco DS / Certum: EV Certificates issued with wrong Business Category
#1420860 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-11-27 · Closed 2023-02-22 · 88% similar
Asseco DS / Certum: CAA Mis-Issuance on mix of wildcard and non-wildcard DNS names in SAN
#1823040 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2023-03-17 · Closed 2023-05-19 · 87% similar
Asseco DS / Certum: Cross-certificate with wrong policy identifier
#1409766 RESOLVED Ca Certificate Compliance Self Reported Incident Certificate Misissuance Opened 2017-10-18 · Closed 2023-02-22 · 85% similar
Asseco DS / Certum: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record
#1524878 RESOLVED Certificate Misissuance Duplicate Or Superseded Opened 2019-02-03 · Closed 2023-02-22 · 84% similar
Asseco DS / Certum: IP in dnsName
#1853663 RESOLVED Certificate Misissuance Opened 2023-09-18 · Closed 2024-05-09 · 83% similar
Asseco DS / Certum: SMIME certificates with wrong organizationIdentifier
#1409764 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-10-18 · Closed 2023-02-22 · 80% similar
Asseco DS / Certum: CAA mis-issuance on critical flag and unknown CAA tag
#2044023 RESOLVED Certificate Misissuance Self Reported Incident Remediation Tracking Opened By Ca Opened 2026-06-01 · Closed 2026-07-02 · 78% similar
Asseco DS / Certum: Cross-Certificates subject encoding discrepancy

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action