← Asseco Data Systems S.A. cases
Bugzilla #1611458 Self Reported Incident

Asseco DS / Certum: Invalid value in SAN dNSName

RESOLVED FIXED Asseco Data Systems S.A.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Asseco Data Systems S.A. (Certum) reported a compliance issue regarding a recently issued SSL certificate that contained an invalid value in the Subject Alternative Name (SAN). During an internal review, it was discovered that an IP address was incorrectly placed in the dNSName field instead of the iPAddress field. The misissued certificate was promptly revoked, and an incident report was promised by January 31, 2020. The CA implemented a procedural change to prevent future occurrences and has committed to further improvements, including a system fix and the removal of exceptions in linting processes.

Model: gpt-4o-mini Generated: 2026-06-13 21:17 UTC Revised: 2026-06-16 18:07 UTC Confidence: 0.85 13 comments
Chronology
  1. Internal review identified misissued certificate with invalid SAN.
  2. CA confirmed the issue and provided a timeline of actions taken.
  3. CA planned a system fix to ensure proper handling of IP addresses.
  4. CA removed all ZLint exceptions and moved to A-labels in Common Name.
Thread Activity
  1. Asseco Data Systems S.A. — Reported an invalid value in SAN during internal review.
  2. Asseco Data Systems S.A. — Provided a detailed timeline of the incident and actions taken.
  3. Asseco Data Systems S.A. — Confirmed system fix to ensure correct SAN handling.
  4. Asseco Data Systems S.A. — Updated that all ZLint exceptions were removed.
  5. Fastly representative — Confirmed that remediation is complete.
Participants
Asseco Data Systems S.A. Community commenter Fastly representative
External References
Similar Local Cases
#1709392 RESOLVED Self Reported Incident Certificate Misissuance Opened 2021-05-04 · Closed 2023-02-22 · 84% similar
Asseco DS / Certum: Invalid stateOrProvinceName field (recurrent incident)
#1409766 RESOLVED Ca Certificate Compliance Self Reported Incident Certificate Misissuance Opened 2017-10-18 · Closed 2023-02-22 · 81% similar
Asseco DS / Certum: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record
#1711208 RESOLVED Self Reported Incident Certificate Misissuance Opened 2021-05-14 · Closed 2023-02-22 · 81% similar
Asseco DS / Certum: Incorrect localityName
#1567062 RESOLVED Self Reported Incident Audit Finding Opened 2019-07-18 · Closed 2023-02-22 · 80% similar
Asseco DS / Certum: inconsistent disclosure of externally-operated intermediate
#1639502 RESOLVED Self Reported Incident Opened 2020-05-20 · Closed 2023-02-22 · 80% similar
Asseco DS / Certum: Incorrect OCSP response encoding
#1815355 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2023-02-07 · Closed 2023-08-16 · 80% similar
Asseco DS / Certum: Cross-Signed non-EV-audited root with an EV-enabled root
#1832093 RESOLVED Self Reported Incident Certificate Misissuance Opened 2023-05-09 · Closed 2023-06-02 · 80% similar
Asseco DS / Certum: Subordinate certificates with sequential serial number
#2021685 RESOLVED Self Reported Incident Opened 2026-03-07 · Closed 2026-04-30 · 80% similar
Asseco DS / Certum: Finding in Routine WebTrust Audit – S/MIME certificates issued with mailbox validation older than 30 days

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action