← Asseco Data Systems S.A. cases
Bugzilla #1865080 Certificate Problem Report

Asseco DS / Certum: TLS EV certificates with incorrect Subject attribute order

RESOLVED FIXED Asseco Data Systems S.A.
AI Summary

Certum issued 138 EV TLS certificates with an incorrect relative order of Subject attributes after the implementation of BR TLS 2.0.0. The issue was identified during a Bugzilla review on November 16, 2023, leading to a halt in certificate issuance and subsequent revocation of all affected certificates. The compliance team has since corrected the error and resumed issuance. A full incident report was published on November 23, 2023, detailing the timeline and actions taken.

Model: gpt-4o-mini Generated: 2026-06-13 21:32 UTC Confidence: 0.90
Chronology
  1. Compliance team identifies mis-issuance of EV TLS certificates.
  2. Certum revokes all affected certificates.
  3. Full incident report published.
Participants
aleksandra.kurosz@assecods.pl bwilson@mozilla.com amir@aaomidi.com dzacharo@harica.gr kateryna.aleksieieva@assecods.pl
External References
Similar Local Cases
#1639502 RESOLVED Certificate Problem Report Opened 2020-05-20 · Closed 2023-02-22 · 59% similar
Asseco DS / Certum: Incorrect OCSP response encoding
#1897630 RESOLVED Certificate Problem Report Opened 2024-05-19 · Closed 2024-08-15 · 56% similar
Entrust: Jurisdiction issue in some EV TLS & Code Signing certificates
#1884461 RESOLVED Certificate Problem Report Opened 2024-03-08 · Closed 2024-05-20 · 56% similar
Microsoft PKI Services: CA Certificates not published in DER Encoded Format
#1885754 RESOLVED Certificate Problem Report Opened 2024-03-16 · Closed 2024-09-13 · 55% similar
Entrust: CPR was not responded to in 24 hours
#1886110 RESOLVED Certificate Problem Report Opened 2024-03-19 · Closed 2025-02-14 · 55% similar
TWCA: Revocation delay for TLS certificates with non-critical basicConstraints
#1839305 RESOLVED Certificate Problem Report Opened 2023-06-20 · Closed 2024-06-30 · 55% similar
Buypass: Domain validation method using externally operated DNS tools
#1495518 RESOLVED Certificate Problem Report Opened 2018-10-01 · Closed 2023-02-22 · 55% similar
Asseco DS / Certum: Unallowed key usage for EC public key (Key Encipherment)
#2021685 RESOLVED Certificate Problem Report Opened 2026-03-07 · Closed 2026-04-30 · 54% similar
Asseco DS / Certum: Finding in Routine WebTrust Audit – S/MIME certificates issued with mailbox validation older than 30 days

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action