← Asseco Data Systems S.A. cases
Bugzilla #1879845 Certificate Misissuance

Asseco DS / Certum: S/MIME certificates with error in subjectAlternativeName

RESOLVED FIXED Asseco Data Systems S.A.
AI Summary

Certum issued 96 S/MIME certificates with incorrect subjectAlternativeName values due to a system error. The issue was identified on February 12, 2024, leading to a suspension of certificate issuance and a subsequent fix deployed on February 13, 2024. All affected certificates were revoked, and the compliance team has since implemented additional testing scenarios to prevent future occurrences. The incident report highlighted both the quick resolution and the oversight during application testing.

Model: gpt-4o-mini Generated: 2026-06-13 21:33 UTC Confidence: 0.90
Chronology
  1. System version with error deployed
  2. Error identified during routine review
  3. System fix deployed and issuance resumed
  4. All affected certificates revoked
  5. Linting for S/MIME certificates implemented
Participants
Kateryna Aleksieieva Aaron Gable Ben Wilson
External References
Similar Local Cases
#1871393 RESOLVED Certificate Misissuance Opened 2023-12-21 · Closed 2024-05-09 · 60% similar
Asseco DS / Certum: Delayed revocation of EV certificates
#1874196 RESOLVED Certificate Misissuance Opened 2024-01-11 · Closed 2024-03-27 · 57% similar
SwissSign: difference in upper and lower case between CN field and SAN
#1766255 RESOLVED Certificate Misissuance Opened 2022-04-25 · Closed 2023-02-22 · 54% similar
SwissSign: Mis-Issuance of S/MIME certificates
#1435770 RESOLVED Certificate Misissuance Opened 2018-02-05 · Closed 2023-02-22 · 54% similar
Asseco DS / Certum: Non-BR-Compliant Issuance - Debian Weak Keys
#1848306 RESOLVED Certificate Misissuance Opened 2023-08-11 · Closed 2023-11-02 · 53% similar
TWCA: CA certificate without EKU
#1644936 RESOLVED Certificate Misissuance Opened 2020-06-11 · Closed 2024-05-09 · 53% similar
Microsoft PKI Services: Certificate Mis-Issuance, Locality Missing
#1600301 RESOLVED Certificate Misissuance Opened 2019-11-29 · Closed 2023-02-22 · 53% similar
Asseco DS / Certum: EV Certificates issued with wrong Business Category
#1611458 RESOLVED Certificate Misissuance Opened 2020-01-24 · Closed 2023-02-22 · 53% similar
Asseco DS / Certum: Invalid value in SAN dNSName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action