Asseco Data Systems (Certum): Failure to revoke intermediate certificates within the BR time period
This case concerns Asseco Data Systems S.A. (Certum) and a failure to revoke intermediate certificates within the required BR time period. The CA stated it became fully aware of the problem from a discussion on mozilla.dev.security.policy on November 21, 2019, and that it had initially missed an earlier Mozilla post dated October 8, 2019. The CA reported that it revoked 15 certificates on November 27, 2019, after deciding to revoke them following a detailed inspection and impact analysis, and stated this was within 7 days of November 21 as required by BR. The CA also stated that the affected certificates were issued between 2008 and 2014 and that there are no valid end-entity certificates issued by these issuers. In the thread, Mozilla participants indicated the disclosure was proactive and that remediation was complete. The bug is marked RESOLVED with resolution FIXED.
- Asseco Data Systems (Certum) became fully aware of the revocation issue via a mozilla.dev.security.policy discussion.
- Asseco Data Systems (Certum) revoked 15 affected intermediate certificates.
- Thread participants indicated remediation was complete and no further questions remained.
- Asseco Data Systems S.A. — Submitted the incident report, stating the CA became fully aware on Nov 21, revoked 15 certificates on Nov 27, and attributed delayed revocation to lack of deep analysis after an Oct 8 Mozilla post.
- Community commenter — Commented that the disclosure was proactive and noted that revocation occurred within 7 days of noticing.
- Fastly representative — Stated it appeared all questions were answered and remediation was complete.