Asseco DS / Certum: commonName not from subjectAltName entries
This case is an incident report from Asseco Data Systems S.A. / Certum describing two SSL certificate misissuances where the certificate Common Name value was not taken from the Subject Alternative Name entries. The CA said it became aware of the issue during its regular crt.sh lint tools review on May 8, 2019, and identified that the first and second problematic certificates were issued on May 6 and May 7, 2019. The CA stated the mistake was caused by a software bug in its certificate data correction process: when an inspector changed request data (e.g., Locality Name or Organizational Unit Name), the Common Name value was removed from Subject Alternative Name. The CA reported that the problematic certificates were revoked, blocked further issuance possibilities by disallowing a correction workaround, and fixed the software with a plan to deploy it at the end of May 2019. To prevent recurrence, the CA added a test scenario to verify that the Common Name value is present in Subject Alternative Name and developed pre-issuance linting, which it later deployed fully automatically in production on July 17, 2019. A Fastly participant indicated that remediation appeared complete, and the bug is resolved as FIXED.
- First SSL certificate with Common Name not from Subject Alternative Name was issued.
- Second SSL certificate with Common Name not from Subject Alternative Name was issued.
- CA became aware of the two misissuances and identified the cause.
- CA deployed fully automatic pre-issuance linting for SSL certificates in production.
- Asseco Data Systems S.A. — Opened an incident report describing how the CA discovered two misissuances, the timeline, the cause (software bug), revocation of the certificates, and remediation steps including software fix and pre-issuance linting.
- Assecods representative — Confirmed the software fix was completed and the bug no longer appeared; pre-issuance linting development was ongoing.
- Community commenter — Asked whether the estimated timeline was 30-June-2019.
- Asseco Data Systems S.A. — Explained the production installation was delayed due to integration with a larger update, with test deployment planned and periodic verification continuing until implementation.
- Community commenter — Requested an update on remediation progress and specific dates.
- Asseco Data Systems S.A. — Confirmed the plan and stated he would keep the participant informed.
- Asseco Data Systems S.A. — Apologized for not sharing test results, confirmed testing was successful, and stated production deployment would occur before July 27.
- Asseco Data Systems S.A. — Reported that fully automatic pre-issuance linting was deployed in production on July 17, 2019.
- Fastly representative — Indicated it appeared all questions were answered and remediation was complete.