Asseco DS / Certum: non-audited intermediate certificate
The bug was opened after the reporter identified an intermediate certificate that was not listed in the scope of an audit statement, based on a Mozilla disclosures page. The reporter stated that the certificate either needed to be revoked and added to OnCRL or included in the scope of appropriate audits and audit statements. The CA representative responded that the certificate later appeared in a new audit statement covering the period March 27, 2018 to March 4, 2019, and that the audit report was updated in CCADB and on the Certum website. A Fastly participant later indicated the issue appeared to be a false positive, noting the certificate was issued on 11-Sept-2018 and appeared on the audit report covering that date, and that CCADB still listed it as covered by the SSL.com audit with a note that it was listed in the Certum audit. The bug was resolved as INVALID.
- A report was filed identifying an intermediate certificate as not covered by an audit statement scope.
- The CA updated audit reporting to include the intermediate certificate in the relevant audit statement period.
- A participant stated the issue appeared to be a false positive based on the certificate’s issuance date and audit coverage.
- Mozilla representative — Reported that an intermediate certificate was not listed in the scope of an audit statement and said it should be revoked/added to OnCRL or included in appropriate audits.
- Assecods representative — Said the certificate appeared in a new audit statement covering March 27, 2018 to March 4, 2019 and that the audit report was updated in CCADB and on the Certum website.
- Assecods representative — Asked whether there were additional questions and requested closing the bug if not.
- Fastly representative — Commented that it appeared to be a false positive and that the certificate was included in the audit report covering its issuance date, with CCADB noting it was listed in the Certum audit.