← Asseco Data Systems S.A. cases
Bugzilla #1639502 Certificate Problem Report

Asseco DS / Certum: Incorrect OCSP response encoding

RESOLVED FIXED Asseco Data Systems S.A.
AI Summary

The case involved an incorrect encoding of the OCSP response by Asseco Data Systems S.A. (Certum), which violated RFC6960 by encoding a default value in the ResponseData.version field. The issue was identified on May 20, 2020, leading to an investigation and subsequent fix implemented by May 21, 2020. Certum confirmed that they ceased issuing OCSP responses with the incorrect encoding and have since enhanced their testing procedures to prevent similar issues in the future. The case was resolved with the implementation of a new linting tool for OCSP services.

Model: gpt-4o-mini Generated: 2026-06-13 21:22 UTC Confidence: 0.95
Chronology
  1. Bug created regarding incorrect OCSP response encoding.
  2. Certum confirmed the issue and implemented a fix.
  3. Certum ceased issuing OCSP responses with the incorrect encoding.
Participants
mpalmer@hezmatt.org wtrapczynski@certum.pl ryan.sleevi@gmail.com bwilson@mozilla.com
External References
Similar Local Cases
#1636141 RESOLVED Certificate Problem Report Opened 2020-05-07 · Closed 2023-02-22 · 64% similar
SwissSign: failure to provide a preliminary report within 24 hours
#1639794 RESOLVED Certificate Problem Report Opened 2020-05-21 · Closed 2023-02-22 · 61% similar
Let's Encrypt: Failure to revoke key-compromised certificate within 24 hours
#1639804 RESOLVED Certificate Problem Report Opened 2020-05-21 · Closed 2023-02-22 · 61% similar
Sectigo: Failure to revoke key-compromised certificate within 24 hours
#1639798 RESOLVED Certificate Problem Report Opened 2020-05-21 · Closed 2023-02-22 · 60% similar
GoDaddy: Failure to revoke key-compromised certificates within 24 hours
#1865080 RESOLVED Certificate Problem Report Opened 2023-11-16 · Closed 2024-01-04 · 59% similar
Asseco DS / Certum: TLS EV certificates with incorrect Subject attribute order
#1722089 RESOLVED Certificate Problem Report Opened 2021-07-23 · Closed 2023-02-22 · 58% similar
SSL.com: Issuance of 3 EV TLS certificates without 2-person validation of the organization information
#1719916 RESOLVED Certificate Problem Report Opened 2021-07-09 · Closed 2023-02-22 · 57% similar
SSL.com: Issuance of an EV TLS certificate with incorrect O Field Value
#1712664 RESOLVED Certificate Problem Report Opened 2021-05-25 · Closed 2023-02-22 · 56% similar
iTrusChina: verification errors for the roots' CRLs(ARL)

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action