Asseco DS / Certum: Invalid stateOrProvinceName field
Certum (Asseco Data Systems S.A.) received a third-party report on 2020-09-26 that it had issued TLS/SSL certificates with an incorrect completion of the stateOrProvinceName field (including “Russian Federation”). Certum analyzed the database, prepared a list of affected certificates for a single corporate customer, informed the customer, and corrected the customer’s dedicated certificate profile by removing the stateOrProvinceName field so it would stop issuing certificates with that value. Certum also coordinated with the customer on revocation timing; it revoked 777 certificates on 2020-10-01 and stated remaining certificates would be revoked up to 2020-10-13. A later thread comment raised that a separate incident report might be needed to cover delayed revocation, and Certum pointed to Bug 1668523 as the place where the revocation delay was described. Certum later reported that all affected certificates had been revoked on 2020-10-09 22:45:50 UTC, and it added test scenarios to verify the stateOrProvinceName field is not added for that profile. The bug was resolved as FIXED and closed by Mozilla on 2021-02-03.
- Certum received a third-party report about incorrectly issued certificates containing an incorrect stateOrProvinceName value.
- Certum removed stateOrProvinceName from the customer’s dedicated certificate profile and the customer began issuing new certificates without that field.
- Certum revoked 777 certificates from the first part of the affected set.
- Certum reported that all affected certificates were revoked.
- Mozilla closed the bug after resolution.
- Assecods representative — Reported that Certum received a third-party report about incorrect stateOrProvinceName issuance and said a detailed response would follow.
- Assecods representative — Provided a timeline: analysis of affected certificates, customer notification, correction of the certificate profile, revocation scheduling, and steps to prevent recurrence.
- Assecods representative — Stated that all affected certificates had been revoked at 2020-10-09 22:45:50 UTC.
- Community commenter — Asked whether a separate incident report should be filed for delayed revocation and questioned the root cause for additional certificates.
- Assecods representative — Responded that the revocation delay was described in Bug 1668523 and explained additional certificates were due to human verification mistakes, with planned system presentation changes and added attention to field correctness.
- Assecods representative — Requested that the bug be closed if there were no further questions.
- Mozilla representative — Announced intent to close the bug on 2021-02-03.