← Asseco Data Systems S.A. cases
Bugzilla #1888689
Certificate Problem Report
Asseco DS / Certum: CRL non-conformance with the TLS BRs
RESOLVED
FIXED
Asseco Data Systems S.A.
AI Summary
Asseco Data Systems S.A. faced an issue where 49 of their Certificate Revocation Lists (CRLs) were found to be non-compliant with the TLS Baseline Requirements (BRs) and RFC 5280. Specifically, these CRLs included a revoked certificates field without any actual revoked certificates listed. The issue was detected through manual investigation and the use of the pkilint tool. Asseco has acknowledged the problem and has committed to submitting an incident report and implementing a fix, which was completed by April 5, 2024.
Chronology
- Incident published
- All incorrect CRLs updated
- Linting for CRL issuing process implemented
Participants
Ryan Dickson
Kateryna Aleksieieva
External References
Similar Local Cases
Asseco DS / Certum: CP/CPS, Revocation Requests Mechanism, Certificate Problem Report, CRL and OCSP disruption
Asseco DS / Certum: Irregularities in Xinchacha/Xcc Brand SSL Certificates
Asseco DS / Certum: Organization Identifier and Country field discrepancies
Asseco DS / Certum: Cross-certificate with wrong policy identifier
Asseco DS / Certum: DNS service outage
Entrust: CRL non-conformance with the TLS BRs
Asseco DS / Certum: Finding in Routine WebTrust Audit – S/MIME certificates issued with mailbox validation older than 30 days
Asseco DS / Certum: CRL URLs disclosed in CCADB do not exactly match the CRL URLs in certificates