Asseco Data Systems (Certum): Intermediate CA certificates not listed in audit report (ALV failures)
Asseco Data Systems S.A. (Certum) opened this case after becoming aware of Audit Letter Validation (ALV) failures for 18 CA certificates based on a discussion on mozilla.dev.security.policy. The CA stated it initially misunderstood the ALV failures as being caused by formatting issues in SHA-256 fingerprints in current audit statements, and later performed a detailed inspection. The CA reported that it identified 15 certificates it believed should be considered non-compliant and analyzed the impact of revocation. It decided to revoke 15 certificates and then revoked them on 2019-11-27, while adding a comment in CCADB for the remaining 3 certificates. The CA also stated that the incident concerns certificates issued between 2008 and 2014 and that all active certificates are included in its current audit reports. The bug was resolved as FIXED, with remediation described as complete in later comments.
- Asseco Data Systems S.A. became fully aware of ALV-related audit issues for certain intermediate CA certificates via a mozilla.dev.security.policy discussion.
- Asseco Data Systems S.A. revoked 15 certificates identified as non-compliant and updated CCADB comments for the remaining certificates.
- Asseco Data Systems S.A. — Reported that the CA became aware of the issue from a mozilla.dev.security.policy discussion and stated it would provide an incident report by 2019-11-29.
- Asseco Data Systems S.A. — Provided a detailed incident response timeline, including that it revoked 15 certificates and added CCADB comments for 3 others, and described the problematic certificates and reasons for ALV failures.
- Community commenter — Noted that the related issue is Bug 1600158 and asked for clarification about future prevention, pending further questions.
- Fastly representative — Confirmed that questions were answered and remediation was complete, supporting closure.