← Asseco Data Systems S.A. cases
Bugzilla #1667986
Certificate Problem Report
Asseco DS / Certum: Invalid stateOrProvinceName field
RESOLVED
FIXED
Asseco Data Systems S.A.
AI Summary
Asseco Data Systems S.A. reported an issue regarding incorrectly issued certificates that contained an invalid value in the stateOrProvinceName field. The problem was identified on September 26, 2020, following a third-party report. Certum promptly initiated an analysis, corrected the certificate profile, and revoked all affected certificates by October 9, 2020. The issue was attributed to human error during the certificate profile setup, and measures have been implemented to prevent similar occurrences in the future.
Chronology
- Received report about incorrect certificate issuance.
- Revoked 777 certificates due to the issue.
- All affected certificates were revoked.
Participants
Aleksandra Kurosz
External References
Similar Local Cases
Asseco DS / Certum: SMIME certificates with wrong organizationIdentifier
Asseco DS / Certum: Incorrect localityName
Asseco DS / Certum: Failure to provide a preliminary report within 24 hours.
Asseco DS / Certum: Cross-certificate with wrong policy identifier
Asseco DS / Certum: Invalid stateOrProvinceName field (recurrent incident)
Asseco DS / Certum: Failure to revoke within 5 days
Asseco DS / Certum: Incorrect localityName
Asseco DS / Certum: Invalid dnsNames