← Asseco Data Systems S.A. cases
Bugzilla #1598277
Certificate Problem Report
Asseco DS / Certum: Intermediate CA certificates not listed in audit report
RESOLVED
FIXED
Asseco Data Systems S.A.
AI Summary
Asseco Data Systems S.A. identified that 18 intermediate CA certificates were not listed in their audit report, with 15 of these certificates deemed non-compliant. The issue was first recognized through a discussion on the Mozilla security policy forum. Following a detailed review, the CA decided to revoke 15 certificates and provided a comprehensive incident report outlining the timeline and actions taken. The case has been resolved with all necessary actions completed.
Chronology
- CA became aware of the problem through a forum discussion.
- CA revoked 15 certificates after detailed inspection.
- All questions answered and remediation confirmed complete.
Participants
Wojciech Trapczyński
Ryan Sleevi
Wayne Thayer
External References
Similar Local Cases
Asseco DS / Certum: Failure to revoke intermediate certificates within the BR time period
Asseco DS / Certum: inconsistent disclosure of externally-operated intermediate
Asseco DS / Certum: Unallowed key usage for EC public key (Key Encipherment)
Asseco DS / Certum: Failure to revoke within 5 days
Asseco DS / Certum: Failure to provide a preliminary report within 24 hours.
Asseco DS / Certum: Corrupted certificates
Asseco DS / Certum: commonName not from subjectAltName entries
Asseco DS / Certum: IP in dnsName