Asseco DS / Certum: inconsistent disclosure of externally-operated intermediate
Asseco Data Systems S.A. (Certum) reported an inconsistency regarding the disclosure of an intermediate certificate that was cross-certified with SSL.com. The issue arose when it was found that the same Subject Public Key Info (SPKI) was associated with different Certificate Policy/Certification Practice Statements (CP/CPS) from both Certum and SSL.com. Following the report, Certum acknowledged the discrepancy and committed to reviewing their disclosures. They subsequently corrected the audit information for the affected certificates and confirmed that no further inconsistencies were found in their intermediate certificates. The case has been resolved with the necessary updates made.
- Asseco disclosed an inconsistency in the CP/CPS information for a cross-certified intermediate certificate.
- Asseco corrected the audit information for the affected certificates.
- Asseco confirmed no additional inconsistencies were found in their intermediate certificates.
- Mm representative — Asseco has disclosed the following intermediate as being operated under the same CP/CPS as parent.
- Asseco Data Systems S.A. — Thank you for reporting this. We will inspect it and share our point of view soon.
- Asseco Data Systems S.A. — We fixed issues reported by crt.sh and set subject audit/CP/CPS information instead of issuer.
- Fastly representative — It appears that all questions have been answered and remediation is complete.