← Asseco Data Systems S.A. cases
Bugzilla #1598277 Self Incident Disclosure

Asseco Data Systems (Certum): Intermediate CA certificates not listed in audit report (ALV failures)

RESOLVED FIXED Asseco Data Systems S.A.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Asseco Data Systems S.A. (Certum) opened this case after becoming aware of Audit Letter Validation (ALV) failures for 18 CA certificates based on a discussion on mozilla.dev.security.policy. The CA stated it initially misunderstood the ALV failures as being caused by formatting issues in SHA-256 fingerprints in current audit statements, and later performed a detailed inspection. The CA reported that it identified 15 certificates it believed should be considered non-compliant and analyzed the impact of revocation. It decided to revoke 15 certificates and then revoked them on 2019-11-27, while adding a comment in CCADB for the remaining 3 certificates. The CA also stated that the incident concerns certificates issued between 2008 and 2014 and that all active certificates are included in its current audit reports. The bug was resolved as FIXED, with remediation described as complete in later comments.

Model: gpt-5.4-nano Generated: 2026-06-13 20:18 UTC Revised: 2026-06-16 18:06 UTC Confidence: 0.86 4 comments
Chronology
  1. Asseco Data Systems S.A. became fully aware of ALV-related audit issues for certain intermediate CA certificates via a mozilla.dev.security.policy discussion.
  2. Asseco Data Systems S.A. revoked 15 certificates identified as non-compliant and updated CCADB comments for the remaining certificates.
Thread Activity
  1. Asseco Data Systems S.A. — Reported that the CA became aware of the issue from a mozilla.dev.security.policy discussion and stated it would provide an incident report by 2019-11-29.
  2. Asseco Data Systems S.A. — Provided a detailed incident response timeline, including that it revoked 15 certificates and added CCADB comments for 3 others, and described the problematic certificates and reasons for ALV failures.
  3. Community commenter — Noted that the related issue is Bug 1600158 and asked for clarification about future prevention, pending further questions.
  4. Fastly representative — Confirmed that questions were answered and remediation was complete, supporting closure.
Participants
Asseco Data Systems S.A. Community commenter Fastly representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1409766 RESOLVED Ca Certificate Compliance Self Reported Incident Certificate Misissuance Opened 2017-10-18 · Closed 2023-02-22 · 69% similar
Asseco DS / Certum: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record
#1511459 RESOLVED Self Reported Incident Opened 2018-11-30 · Closed 2023-02-22 · 63% similar
Asseco DS / Certum: Corrupted certificates
#1639502 RESOLVED Self Reported Incident Opened 2020-05-20 · Closed 2023-02-22 · 60% similar
Asseco DS / Certum: Incorrect OCSP response encoding
#1709392 RESOLVED Self Reported Incident Certificate Misissuance Opened 2021-05-04 · Closed 2023-02-22 · 60% similar
Asseco DS / Certum: Invalid stateOrProvinceName field (recurrent incident)
#1667684 RESOLVED Self Reported Incident Opened 2020-09-27 · Closed 2023-02-22 · 59% similar
Asseco DS / Certum: Failure to provide a preliminary report within 24 hours.
#1600158 RESOLVED Ca Certificate Compliance Delayed Revocation Opened 2019-11-28 · Closed 2023-02-22 · 55% similar
Asseco DS / Certum: Failure to revoke intermediate certificates within the BR time period
#1832093 RESOLVED Self Reported Incident Certificate Misissuance Opened 2023-05-09 · Closed 2023-06-02 · 54% similar
Asseco DS / Certum: Subordinate certificates with sequential serial number
#1958645 RESOLVED Ca Security Vulnerability Opened 2025-04-05 · Closed 2025-06-10 · 54% similar
Asseco DS / Certum: DNS service outage

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action