← Asseco Data Systems S.A. cases
Bugzilla #1815355 Ca Certificate Compliance Self Reported Incident

Asseco DS / Certum: Cross-Signed non-EV-audited root with an EV-enabled root

RESOLVED FIXED Asseco Data Systems S.A.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case involves Asseco Data Systems S.A. (Certum) disclosing a compliance issue regarding cross-signed certificates that were capable of issuing EV TLS certificates but had not been audited according to EV criteria. The issue was identified when a bug was filed on February 7, 2023. Certum acknowledged the oversight and outlined a timeline of actions taken to address the problem, including ceasing the issuance of new cross-certificates until the issue is resolved. The CA confirmed that no EV certificates had been issued from the affected hierarchy and committed to including the necessary audits in future periods. The case was resolved with a plan to ensure compliance moving forward, and a lessons learned statement was shared with the community.

Model: gpt-4o-mini Generated: 2026-06-13 21:29 UTC Revised: 2026-06-16 18:09 UTC Confidence: 0.85 23 comments
Chronology
  1. Certum issues a cross-certificate for SSL Corporation.
  2. Bug filed regarding compliance issue.
  3. Lessons learned statement posted to MDSP.
Thread Activity
  1. Mozilla representative — Reported that Certum enabled EV TLS certificates without proper audits.
  2. Assecods representative — Acknowledged the issue and provided a timeline of actions taken.
  3. Mozilla representative — Requested a plan for replacing and revoking the certificates.
  4. SSL.com — Confirmed actions taken and lessons learned shared with the community.
Participants
Mozilla representative Assecods representative SSL.com
Similar Local Cases
#1667684 RESOLVED Self Reported Incident Opened 2020-09-27 · Closed 2023-02-22 · 98% similar
Asseco DS / Certum: Failure to provide a preliminary report within 24 hours.
#1711208 RESOLVED Self Reported Incident Certificate Misissuance Opened 2021-05-14 · Closed 2023-02-22 · 97% similar
Asseco DS / Certum: Incorrect localityName
#1709392 RESOLVED Self Reported Incident Certificate Misissuance Opened 2021-05-04 · Closed 2023-02-22 · 96% similar
Asseco DS / Certum: Invalid stateOrProvinceName field (recurrent incident)
#1409766 RESOLVED Ca Certificate Compliance Self Reported Incident Certificate Misissuance Opened 2017-10-18 · Closed 2023-02-22 · 91% similar
Asseco DS / Certum: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record
#1639502 RESOLVED Self Reported Incident Opened 2020-05-20 · Closed 2023-02-22 · 91% similar
Asseco DS / Certum: Incorrect OCSP response encoding
#1879845 RESOLVED Ca Certificate Compliance Opened 2024-02-12 · Closed 2024-10-02 · 91% similar
Asseco DS / Certum: S/MIME certificates with error in subjectAlternativeName
#1904494 RESOLVED Ca Certificate Compliance Ca Documents Audit Document Remediation Tracking Opened 2024-06-25 · Closed 2024-09-04 · 90% similar
Asseco DS / Certum: Cross-certificate not included in 2024 S/MIME Audit statement
#1832093 RESOLVED Self Reported Incident Certificate Misissuance Opened 2023-05-09 · Closed 2023-06-02 · 87% similar
Asseco DS / Certum: Subordinate certificates with sequential serial number

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action