← Asseco Data Systems S.A. cases
Bugzilla #1718680
Technical Compliance
Asseco DS / Certum: Forward dating certificates (notBefore in the future)
RESOLVED
FIXED
Asseco Data Systems S.A.
AI Summary
Asseco Data Systems S.A. was found to be forward-dating certificates, setting the 'notBefore' date to a future date, which is against Mozilla's guidelines. The practice was intended to help server operators manage TLS certificates but raised compliance concerns. Following discussions, Asseco DS committed to stop this practice and implemented changes to their system to prevent future occurrences. The case has been resolved with the necessary updates deployed.
Chronology
- Case opened regarding forward dating of certificates.
- New version of the application deployed, preventing future forward dating.
- Case closed.
Participants
Ryan Sleevi
Aleksandra Kurosz
Wojciech Trapczynski
Ben Wilson
External References
Similar Local Cases
E-Tugra: Forbidden Domain Validation Method 3.2.2.4.6
Telekom Security: Finding in 2020 ETSI-Audit regarding weekly review of changes to configurations
Asseco DS / Certum: non-audited intermediate certificate
GoDaddy: DV certificates with organizationalUnit field in subject
Firmaprofesional: 2022 - Define Device Obsolescence Process
Let's Encrypt: Failure to audit log subscriber certificate OCSP updates
Sectigo: Late termination of privileged access to Certificate Systems
Firmaprofesional: 2022 - Title field