← Asseco Data Systems S.A. cases
Bugzilla #1667684
Certificate Problem Report
Asseco DS / Certum: Failure to provide a preliminary report within 24 hours.
RESOLVED
FIXED
Asseco Data Systems S.A.
AI Summary
Asseco Data Systems S.A. (Certum) failed to provide a preliminary report within the required 24-hour timeframe after receiving a Certificate Problem Report regarding the misissuance of certificates. The issue arose when a third party reported that the stateOrProvinceName field contained 'Russian Federation', which is not compliant with the Baseline Requirements. Certum acknowledged the oversight and has since updated their procedures to ensure timely responses to such reports. The case has been resolved with the implementation of new protocols to prevent future occurrences.
Chronology
- Third party reported certificate issue to Certum.
- Certum acknowledged the incident and began analysis.
- Certum updated procedures to ensure compliance.
- Bug was closed after resolution.
Participants
George [:fozzie]
Wojciech Trapczyński
Aleksandra Kurosz
Ryan Sleevi
B. Wilson
External References
Similar Local Cases
Asseco DS / Certum: Failure to revoke within 5 days
Asseco DS / Certum: Invalid stateOrProvinceName field (recurrent incident)
Asseco DS / Certum: Failure to revoke intermediate certificates within the BR time period
Asseco DS / Certum: Incorrect localityName
Asseco DS / Certum: Subordinate certificates with sequential serial number
Asseco DS / Certum: Incorrect localityName
Asseco DS / Certum: IP in dnsName
Asseco DS / Certum: commonName not from subjectAltName entries