Asseco DS / Certum: S/MIME certificates issued with incorrect organizationIdentifier
Asseco Data Systems S.A. (Certum) reported that it identified S/MIME certificates that were issued with an incorrect organizationIdentifier. The CA said it first became aware of the issue on September 17, 2023, when its Certum Validation Team found two incorrectly issued certificates during a routine check. The CA stated that it immediately revoked the two affected certificates and informed customers so they could submit new certificate requests. The CA reported that the misissuance was caused by a combination of factors, including a validator that could alert but did not prevent issuance, and a Validation Officer misunderstanding instructions related to using EUID versus the intended fields in the organizationIdentifier. The CA also reported additional training for the Validation Team and planned an additional validator to block issuance when organizationIdentifier errors are detected. The CA later confirmed that no further misissuance had occurred and that the analysis found no more errors. The bug was resolved as FIXED and Mozilla indicated it would close it on or about October 18, 2023 unless there were community questions.
- Certum Validation Team identified two S/MIME certificates with incorrect organizationIdentifier during a routine check.
- The CA revoked the two affected certificates and enabled customers to request corrected replacements.
- Compliance began analysis to determine whether additional incorrectly issued certificates existed.
- Additional training was conducted for the Validation Team regarding organizationIdentifier.
- The CA completed its analysis and reported no further errors.
- Mozilla indicated it would close the bug on or about 18-Oct-2023 unless there were community questions.
- Assecods representative — Reported that on September 17 the Validation Team informed the CA about several S/MIME certificates with incorrect OrganizationIdentifier, identified two issued certificates, and stated they were immediately revoked with customer notification; promised a detailed report by September 29, 2023.
- Assecods representative — Provided a detailed incident timeline, described the causes (validator signaling but not preventing issuance and misunderstanding of EUID usage), listed affected certificate serial numbers, and described remediation steps including training and a planned blocking validator.
- Assecods representative — Stated there were no additional updates for the bug.
- Assecods representative — Confirmed no new misissuance had occurred and asked whether the bug could be closed.
- Mozilla representative — Said Mozilla would close the bug on or about 18-Oct-2023 unless there were questions from the community.