← Asseco Data Systems S.A. cases
Bugzilla #1611458 Certificate Misissuance

Asseco DS / Certum: Invalid value in SAN dNSName

RESOLVED FIXED Asseco Data Systems S.A.
AI Summary

Asseco Data Systems S.A. reported a misissuance of an SSL certificate where an IP address was incorrectly placed in the dNSName field instead of the iPAddress field. This issue was identified during an internal review, and the misissued certificate was revoked promptly. The CA has since implemented procedural changes to prevent recurrence, including a system fix and a commitment to stop issuing U-Labels in the Common Name field. The incident highlights the importance of validating dNSNames to avoid similar issues in the future.

Model: gpt-4o-mini Generated: 2026-06-13 21:17 UTC Confidence: 0.90
Chronology
  1. Installed a new version of the certificate management application.
  2. Discovered a bug affecting SSL certificate issuance with IP addresses.
  3. Introduced a workaround for the identified bug.
  4. Identified the misissued certificate during an internal review.
  5. Revoked the misissued certificate.
  6. Planned installation of a system fix to prevent future misissuance.
  7. Moved to A-labels in the Common Name and removed all ZLint exceptions.
Participants
Wojciech Trapczyński Ryan Sleevi Wayne Thayer
External References
Similar Local Cases
#1409766 RESOLVED Certificate Misissuance Opened 2017-10-18 · Closed 2023-02-22 · 73% similar
Asseco DS / Certum: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record
#1435770 RESOLVED Certificate Misissuance Opened 2018-02-05 · Closed 2023-02-22 · 60% similar
Asseco DS / Certum: Non-BR-Compliant Issuance - Debian Weak Keys
#1600301 RESOLVED Certificate Misissuance Opened 2019-11-29 · Closed 2023-02-22 · 60% similar
Asseco DS / Certum: EV Certificates issued with wrong Business Category
#1551372 RESOLVED Certificate Misissuance Opened 2019-05-14 · Closed 2023-02-22 · 59% similar
Telia: "Some-State" in stateOrProvinceName
#1524050 RESOLVED Certificate Misissuance Opened 2019-01-30 · Closed 2023-02-22 · 58% similar
Telia: Misissued certificate - invalid dnsName
#1644936 RESOLVED Certificate Misissuance Opened 2020-06-11 · Closed 2024-05-09 · 58% similar
Microsoft PKI Services: Certificate Mis-Issuance, Locality Missing
#1523186 RESOLVED Certificate Misissuance Opened 2019-01-27 · Closed 2023-02-22 · 58% similar
KIR S.A.: Misissuance - missing OCSP AIA, Validity > 825 days
#1552562 RESOLVED Certificate Misissuance Opened 2019-05-17 · Closed 2023-02-22 · 58% similar
Entrust: Question marks in certificate O and L fields

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action