← Asseco Data Systems S.A. cases
Bugzilla #1600301
Certificate Misissuance
Asseco DS / Certum: EV Certificates issued with wrong Business Category
RESOLVED
FIXED
Asseco Data Systems S.A.
AI Summary
Asseco Data Systems S.A. identified that 12 EV SSL certificates were incorrectly issued with the business category 'Non-Commercial Entity'. The issue was reported on November 25, 2019, leading to a review and confirmation of the misissued certificates. The CA took steps to revoke the problematic certificates and trained their validation specialists on the correct interpretation of business categories. All affected certificates have since been revoked, and the CA has committed to updating their documentation to prevent future occurrences.
Chronology
- Notification received about misissued certificates.
- Quality team initiated a manual review of certificates.
- Customers notified to revoke problematic certificates.
- Documentation updated to reflect correct business category guidelines.
Participants
Aleksandra Kapinos
Ryan Sleevi
W. Thayer
External References
Similar Local Cases
Asseco DS / Certum: Invalid value in SAN dNSName
SwissSign: Misissuance of Intermediate Certificates because of incorrect organizationIdentifier
Asseco DS / Certum: EV certificate mis-issue
Amazon Trust Services: No Space In Private Organization
Asseco DS / Certum: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record
Asseco DS / Certum: CAA Mis-Issuance on mix of wildcard and non-wildcard DNS names in SAN
SwissSign: Misissuance of Leaf Certificates because of incorrect postcode
Entrust: Certificate Issued with Incorrect Country Code