Asseco DS / Certum: Delayed revocation of EV certificates
This case concerns Certum (Asseco Data Systems S.A.) issuing 138 EV TLS certificates with an incorrect relative order of Subject attributes after September 15, 2023. The incident was linked to a prior bug (1865080) showing that the certificates were not revoked within the time specified by the CA/B Forum Baseline Requirements. Certum reported that it revoked all affected certificates on November 21, 2023, and provided a timeline and root cause analysis for the revocation delay. In its analysis, Certum stated it had misunderstood the revocation deadline by counting full days rather than distinguishing hours versus days, which it said led to the delay. The bug was created to clarify the situation, and Certum also stated it would change internal instructions from “5 days” to “120 hours” for revocation. The bug is marked RESOLVED with resolution FIXED, and Mozilla indicated it would be closed on 29-Dec-2023 unless further discussion was needed.
- Certum began issuing EV TLS certificates with an incorrect relative order of Subject attributes.
- Certum revoked all affected EV TLS certificates.
- Mozilla closed the loop on the bug after discussion, with no further updates expected.
- Assecods representative — Created an incident report attachment describing 138 affected EV TLS certificates, the revocation timeline, root cause analysis for the delayed revocation, and an action item to change internal revocation instructions from 5 days to 120 hours.
- Mozilla representative — Stated the bug would be closed on 29-Dec-2023 unless further discussion was needed.
- Assecods representative — Confirmed there were no additional updates for the bug.