← Asseco Data Systems S.A. cases
Bugzilla #1832093
Certificate Problem Report
Asseco DS / Certum: Subordinate certificates with sequential serial number
RESOLVED
FIXED
Asseco Data Systems S.A.
AI Summary
Asseco Data Systems S.A. identified an issue during a periodic self-audit where three subordinate certificates were found to have sequential serial numbers, which may indicate insufficient entropy in their generation. The CA took immediate action, revoking two of the certificates and implementing fixes to prevent future occurrences. A comprehensive review of their database confirmed no additional affected certificates. The final certificate was revoked as scheduled, and the issue was resolved.
Chronology
- Discovery of sequential serial numbers during self-audit
- Revocation of the first subordinate certificate
- Revocation of the second subordinate certificate
- Revocation of the third subordinate certificate
- Case resolved
Participants
Wojciech Trapczyński
Matthias
B. Wilson
External References
Similar Local Cases
Asseco DS / Certum: Failure to provide a preliminary report within 24 hours.
Asseco DS / Certum: Unallowed key usage for EC public key (Key Encipherment)
Asseco DS / Certum: commonName not from subjectAltName entries
Asseco DS / Certum: Cross-Certificates subject encoding discrepancy
Asseco DS / Certum: Corrupted certificates
Asseco DS / Certum: Cross-certificate with wrong policy identifier
Asseco DS / Certum: Intermediate CA certificates not listed in audit report
Asseco DS / Certum: Failure to revoke within 5 days