← Asseco Data Systems S.A. cases
Bugzilla #1823040
Certificate Problem Report
Asseco DS / Certum: Cross-certificate with wrong policy identifier
RESOLVED
FIXED
Asseco Data Systems S.A.
AI Summary
Asseco Data Systems S.A. identified a cross-certificate issued for SHECA that contained an incorrect policy identifier. The issue was discovered during the analysis of another bug and led to the decision to revoke the problematic certificate. A new cross-certificate with the correct policy identifier was issued on March 28, 2023, and the problematic certificate was revoked on April 28, 2023. The CA has committed to ensuring that such mis-issuances do not occur in the future by implementing additional safeguards.
Chronology
- Bug reported regarding cross-certificate with wrong policy identifier.
- CA provided a timeline of actions taken in response to the issue.
- New cross-certificate issued for SHECA.
- Problematic cross-certificate revoked.
Participants
Wojciech Trapczyński
Ryan Dickson
Aleksandra Kurosz
External References
Similar Local Cases
Asseco DS / Certum: Failure to provide a preliminary report within 24 hours.
Asseco DS / Certum: Failure to revoke within 5 days
Asseco DS / Certum: Incorrect localityName
Asseco DS / Certum: SMIME certificates with wrong organizationIdentifier
Asseco DS / Certum: Invalid stateOrProvinceName field
Asseco DS / Certum: Cross-Certificates subject encoding discrepancy
Asseco DS / Certum: Subordinate certificates with sequential serial number
Asseco DS / Certum: CRL non-conformance with the TLS BRs