Asseco DS / Certum: Cross-Signed non-EV-audited root with an EV-enabled root
This case involves Asseco Data Systems S.A. (Certum) disclosing a compliance issue regarding cross-signed certificates that were capable of issuing EV TLS certificates but had not been audited according to EV criteria. The issue was identified when a bug was filed on February 7, 2023. Certum acknowledged the oversight and outlined a timeline of actions taken to address the problem, including ceasing the issuance of new cross-certificates until the issue is resolved. The CA confirmed that no EV certificates had been issued from the affected hierarchy and committed to including the necessary audits in future periods. The case was resolved with a plan to ensure compliance moving forward, and a lessons learned statement was shared with the community.
- Certum issues a cross-certificate for SSL Corporation.
- Bug filed regarding compliance issue.
- Lessons learned statement posted to MDSP.
- Mozilla representative — Reported that Certum enabled EV TLS certificates without proper audits.
- Assecods representative — Acknowledged the issue and provided a timeline of actions taken.
- Mozilla representative — Requested a plan for replacing and revoking the certificates.
- SSL.com — Confirmed actions taken and lessons learned shared with the community.