← Asseco Data Systems S.A. cases
Bugzilla #1826363 Delayed Revocation

Asseco Data Systems / Certum: Delayed revocation of SSL.COM cross certificate

RESOLVED FIXED Asseco Data Systems S.A.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case is a continuation of Bug 1815355 and concerns delayed revocation of an SSL.COM cross certificate. The CA (Certum/Asseco Data Systems) stated that it analyzed the issue and contacted SSL Corporation to confirm its findings. In the incident report, Certum explained that it decided not to revoke the cross certificate because it expires soon in September 2023, and because it considered the risk negligible given the remaining short validity period and the number of end customers that would need to transfer to a new cross certificate. As corrective actions, Certum said it would change the cross-certification contract provision to explicitly state a 7-day revocation requirement for the cross certificate, regardless of the reason for revocation, and require partners to inform end customers that revocation will take 7 days. The CA also stated it would not issue any new cross certificate until the reported problem was resolved. The bug was resolved as FIXED, and Mozilla indicated it intended to close the bug unless there were additional questions or concerns.

Model: gpt-5.4-nano Generated: 2026-06-13 21:30 UTC Revised: 2026-06-16 18:10 UTC Confidence: 0.86 7 comments
Chronology
  1. Bug 1815355 was created, initiating the reported issue that this case continues.
  2. Certum began analyzing the cross-certificate problem and contacted SSL Corporation to confirm findings.
  3. This continuation bug (1826363) was opened by Asseco Data Systems / Certum.
  4. Certum provided the incident report describing the decision not to revoke and the corrective contract changes.
  5. Mozilla planned to close the bug if no further questions or concerns were raised.
Thread Activity
  1. aleksandra.kurosz@assecods.pl — Opened the continuation bug and said they were working on an answer and action plan with SSL.COM, with regular updates to follow.
  2. ryandickson@google.com — Requested an incident report using the CCADB incident-report format, including root cause analysis and steps to prevent recurrence.
  3. aleksandra.kurosz@assecods.pl — Said the incident report would be provided no later than April 19, 2023.
  4. aleksandra.kurosz@assecods.pl — Provided an incident report including a timeline, stated that Certum would not issue new cross certificates until the problem was resolved, explained why it decided not to revoke the cross certificate, and described corrective contract and partner notification actions.
  5. aleksandra.kurosz@assecods.pl — Asked whether there were any questions and noted there were no further updates.
  6. aleksandra.kurosz@assecods.pl — Asked if the bug could be closed if there were no questions.
  7. bwilson@mozilla.com — Indicated intent to close the bug the following Wednesday (7 June 2023) unless there were additional questions or concerns.
Participants
aleksandra.kurosz@assecods.pl ryandickson@google.com bwilson@mozilla.com
Related Bugzilla IDs Mentioned
Similar Local Cases
#1826363 RESOLVED Delayed Revocation Opened 2023-04-04 · Closed 2023-06-08 · 100% similar
Asseco DS / Certum: Delayed revocation of SSL.COM cross certificate
#1825734 RESOLVED Delayed Revocation Opened 2023-03-31 · Closed 2023-06-01 · 100% similar
Asseco DS / Certum: Delayed revocation of SHECA cross certificate
#1667986 RESOLVED Delayed Revocation Opened 2020-09-29 · Closed 2023-02-22 · 97% similar
Asseco DS / Certum: Invalid stateOrProvinceName field
#1871393 RESOLVED Delayed Revocation Opened 2023-12-21 · Closed 2024-05-09 · 97% similar
Asseco DS / Certum: Delayed revocation of EV certificates
#1668523 RESOLVED Delayed Revocation Revocation Issue Opened 2020-10-01 · Closed 2023-02-22 · 95% similar
Asseco DS / Certum: Failure to revoke within 5 days
#1524195 RESOLVED Certificate Misissuance Delayed Revocation Opened 2019-01-31 · Closed 2023-02-22 · 80% similar
Asseco DS / Certum: Invalid dnsNames
#1600158 RESOLVED Ca Certificate Compliance Delayed Revocation Opened 2019-11-28 · Closed 2023-02-22 · 80% similar
Asseco DS / Certum: Failure to revoke intermediate certificates within the BR time period
#2023190 RESOLVED Delayed Revocation Opened 2026-03-13 · Closed 2026-04-19 · 79% similar
Asseco DS / Certum: Delayed revocation of S/MIME certificates issued with mailbox validation older than 30 days

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action