← Asseco Data Systems S.A. cases
Bugzilla #1865080
Certificate Misissuance
Asseco DS / Certum: TLS EV certificates with incorrect Subject attribute order
RESOLVED
FIXED
Asseco Data Systems S.A.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
Asseco Data Systems S.A. (Certum) discovered that it had issued 138 EV TLS certificates with an incorrect relative order of Subject attributes, violating CA/B Forum Baseline Requirements. The issue was identified during a weekly Bugzilla review on November 16, 2023, prompting Certum to halt further issuance of EV TLS certificates. All affected certificates were subsequently revoked by November 21, 2023, after the error was corrected. A full incident report was published on November 23, 2023, detailing the timeline and actions taken to address the compliance failure.
Chronology
- Certum identified the mis-issuance of EV TLS certificates with incorrect Subject attribute order.
- Certum revoked all affected certificates.
- Certum published a full incident report.
Thread Activity
- Assecods representative — Certum's compliance team verified the mis-issuance of EV TLS certificates.
- Assecods representative — Certum published a full incident report detailing the mis-issuance.
- Assecods representative — Certum acknowledged the incorrect interpretation of the 5-day revocation requirement.
- Mozilla representative — The matter was closed following the opening of a new bug regarding delayed revocation.
Participants
Assecods representative
Mozilla representative
Community commenter
HARICA
External References
Similar Local Cases
Asseco DS / Certum: Incorrect localityName
Asseco DS / Certum: Invalid stateOrProvinceName field (recurrent incident)
Asseco DS / Certum: Organization Identifier and Country field discrepancies
Asseco DS / Certum: Subordinate certificates with sequential serial number
IdenTrust: unintended creation of a Root CA certificate
Telia: Certificates Issued with lower case value in subject:countryName
Chunghwa Telecom: Failure to check restrictive CAA record during Migration
Entrust: CPS typographical (text placement) error