← Asseco Data Systems S.A. cases
Bugzilla #1879845
Ca Certificate Compliance
Asseco DS / Certum: S/MIME certificates with error in subjectAlternativeName
RESOLVED
FIXED
Asseco Data Systems S.A.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
Asseco Data Systems S.A. (Certum) identified a compliance issue involving the issuance of 96 S/MIME certificates with incorrect subjectAlternativeName values. The error was discovered during a routine review on February 12, 2024, leading to an immediate suspension of certificate issuance. A system fix was deployed on February 13, 2024, allowing the resumption of issuance after all affected certificates were revoked. The CA provided a detailed incident report outlining the timeline, impact, and corrective actions taken, including the implementation of new test scenarios to prevent future occurrences.
Chronology
- Certum discovered misissuance of S/MIME certificates with incorrect subjectAlternativeName.
- System fix deployed to correct the issue.
- All affected certificates were revoked.
Thread Activity
- Assecods representative — Certum's compliance team found that Certum issued a number of S/MIME certificates with incorrect subjectAlternativeName.
- Assecods representative — Incident report provided detailing the misissuance and corrective actions.
- Internet Security Research Group — Requested clarification on the content of the subjectAlternativeName.
- Assecods representative — Confirmed implementation of linting for S/MIME certificates.
Participants
Assecods representative
Internet Security Research Group
Mozilla representative
External References
Similar Local Cases
Asseco DS / Certum: Cross-certificate not included in 2024 S/MIME Audit statement
Asseco DS / Certum: CP/CPS, Revocation Requests Mechanism, Certificate Problem Report, CRL and OCSP disruption
Asseco DS / Certum: Organization Identifier and Country field discrepancies
Asseco DS / Certum: Cross-Signed non-EV-audited root with an EV-enabled root
Asseco DS / Certum: Unallowed key usage for EC public key (Key Encipherment)
Asseco DS / Certum: CRL non-conformance with the TLS BRs
Buypass: TLS certificates with incorrect Subject attribute order
Asseco DS / Certum: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record