← Asseco Data Systems S.A. cases
Bugzilla #1853663
Certificate Problem Report
Asseco DS / Certum: SMIME certificates with wrong organizationIdentifier
RESOLVED
FIXED
Asseco Data Systems S.A.
AI Summary
Asseco Data Systems S.A. identified two S/MIME certificates issued with incorrect OrganizationIdentifiers during a routine check on September 17, 2023. The certificates were promptly revoked, and clients were notified to submit new requests. The misissuance was attributed to a misunderstanding by the Validation Officer regarding the use of the EUID number. Additional training and a new validator are being implemented to prevent future occurrences. The issue has been resolved, and no further misissuance has been reported.
Chronology
- Validation Team discovered two incorrectly issued certificates.
- Bug created to track the issue.
- Detailed report on the incident submitted.
- Confirmation received that no new misissuance has occurred.
Participants
Aleksandra Kurosz
B Wilson
External References
Similar Local Cases
Asseco DS / Certum: Incorrect localityName
Asseco DS / Certum: Invalid stateOrProvinceName field
Asseco DS / Certum: Cross-certificate with wrong policy identifier
Asseco DS / Certum: Incorrect localityName
Asseco DS / Certum: Failure to provide a preliminary report within 24 hours.
Asseco DS / Certum: Failure to revoke within 5 days
Asseco DS / Certum: Invalid stateOrProvinceName field (recurrent incident)
Asseco DS / Certum: Organization Identifier and Country field discrepancies