← Asseco Data Systems S.A. cases
Bugzilla #1879845 Ca Certificate Compliance

Asseco DS / Certum: S/MIME certificates with error in subjectAlternativeName

RESOLVED FIXED Asseco Data Systems S.A.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Asseco Data Systems S.A. (Certum) identified a compliance issue involving the issuance of 96 S/MIME certificates with incorrect subjectAlternativeName values. The error was discovered during a routine review on February 12, 2024, leading to an immediate suspension of certificate issuance. A system fix was deployed on February 13, 2024, allowing the resumption of issuance after all affected certificates were revoked. The CA provided a detailed incident report outlining the timeline, impact, and corrective actions taken, including the implementation of new test scenarios to prevent future occurrences.

Model: gpt-4o-mini Generated: 2026-06-13 21:33 UTC Revised: 2026-06-16 18:11 UTC Confidence: 0.90 21 comments
Chronology
  1. Certum discovered misissuance of S/MIME certificates with incorrect subjectAlternativeName.
  2. System fix deployed to correct the issue.
  3. All affected certificates were revoked.
Thread Activity
  1. Assecods representative — Certum's compliance team found that Certum issued a number of S/MIME certificates with incorrect subjectAlternativeName.
  2. Assecods representative — Incident report provided detailing the misissuance and corrective actions.
  3. Internet Security Research Group — Requested clarification on the content of the subjectAlternativeName.
  4. Assecods representative — Confirmed implementation of linting for S/MIME certificates.
Participants
Assecods representative Internet Security Research Group Mozilla representative
External References
Similar Local Cases
#1904494 RESOLVED Ca Certificate Compliance Ca Documents Audit Document Remediation Tracking Opened 2024-06-25 · Closed 2024-09-04 · 98% similar
Asseco DS / Certum: Cross-certificate not included in 2024 S/MIME Audit statement
#1909203 RESOLVED Ca Certificate Compliance Incident Opened 2024-07-22 · Closed 2025-05-13 · 97% similar
Asseco DS / Certum: CP/CPS, Revocation Requests Mechanism, Certificate Problem Report, CRL and OCSP disruption
#1917571 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2024-09-09 · Closed 2024-11-06 · 96% similar
Asseco DS / Certum: Organization Identifier and Country field discrepancies
#1815355 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2023-02-07 · Closed 2023-08-16 · 91% similar
Asseco DS / Certum: Cross-Signed non-EV-audited root with an EV-enabled root
#1495518 RESOLVED Ca Certificate Compliance Opened 2018-10-01 · Closed 2023-02-22 · 87% similar
Asseco DS / Certum: Unallowed key usage for EC public key (Key Encipherment)
#1888689 RESOLVED Ca Certificate Compliance Incident Opened 2024-03-29 · Closed 2024-10-02 · 82% similar
Asseco DS / Certum: CRL non-conformance with the TLS BRs
#1864204 RESOLVED Ca Certificate Compliance Opened 2023-11-10 · Closed 2024-05-10 · 81% similar
Buypass: TLS certificates with incorrect Subject attribute order
#1409766 RESOLVED Ca Certificate Compliance Self Reported Incident Certificate Misissuance Opened 2017-10-18 · Closed 2023-02-22 · 81% similar
Asseco DS / Certum: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action