← Asseco Data Systems S.A. cases
Bugzilla #1815355 Policy Compliance

Asseco DS / Certum: Cross-Signed non-EV-audited root with an EV-enabled root

RESOLVED FIXED Asseco Data Systems S.A.
AI Summary

The case involves Asseco Data Systems S.A. (Certum) issuing cross-signed certificates that enabled EV treatment without the required audits. The issue was raised by Kathleen Wilson, highlighting that the cross-certificates were capable of issuing EV TLS certificates but had not been audited accordingly since their issuance in 2018. Certum acknowledged the oversight and confirmed that they would include the EV audit scope in future audits. The cross-certificates are set to expire in September 2023, and corrective measures have been established to prevent similar issues in the future.

Model: gpt-4o-mini Generated: 2026-06-13 21:29 UTC Confidence: 0.90
Chronology
  1. Bug filed regarding cross-signed certificates without EV audits.
  2. Discussion on corrective actions and audit scope.
  3. Update on lessons learned and community response preparation.
  4. Lessons Learned statement posted to MDSP.
  5. Bug closure planned.
Participants
Kathleen Wilson Aleksandra Kurosz Ben Wilson Thomas Zermeno
Similar Local Cases
#1717034 RESOLVED Policy Compliance Opened 2021-06-17 · Closed 2023-02-22 · 56% similar
Asseco DS / Certum: CPS does not refer to BR domain validation methods
#1518560 RESOLVED Policy Compliance Opened 2019-01-08 · Closed 2023-02-22 · 52% similar
Asseco DS / Certum: Use of forbidden subjectPublicKeyInfo algorithm
#1586795 RESOLVED Policy Compliance Opened 2019-10-07 · Closed 2023-02-22 · 50% similar
NetLock: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy
#1693930 RESOLVED Policy Compliance Opened 2021-02-20 · Closed 2023-02-22 · 49% similar
Microsoft PKI Services: Policy Documentation, Failure to update Subscriber Certificate Max Validity Period
#1935393 RESOLVED Policy Compliance Opened 2024-12-05 · Closed 2025-01-29 · 48% similar
Asseco DS / Certum: Failure to Update Policy Documents within 365 Days
#1772412 RESOLVED Policy Compliance Opened 2022-06-02 · Closed 2023-03-20 · 48% similar
iTrusChina: Failure to Respond to May 2022 Survey
#1391864 RESOLVED Policy Compliance Opened 2017-08-19 · Closed 2023-02-22 · 48% similar
Staat der Nederlandend / PKIoverheid: Non-BR-Compliant Certificate Issuance
#1391429 RESOLVED Policy Compliance Opened 2017-08-17 · Closed 2024-02-27 · 48% similar
GoDaddy: Non-BR-Compliant Certificate Issuance

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action