← Asseco Data Systems S.A. cases
Bugzilla #1888689 Ca Certificate Compliance Incident

Asseco DS / Certum: CRL non-conformance with the TLS BRs

RESOLVED FIXED Asseco Data Systems S.A.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Asseco Data Systems S.A. disclosed a compliance issue regarding their Certificate Revocation Lists (CRLs), which were found to violate the TLS Baseline Requirements (BRs) and RFC 5280. Specifically, 49 CRLs contained the revoked certificates field without any revoked certificates present. The issue was detected through manual investigation and the use of the pkilint tool. Following the discovery, Asseco initiated an incident report and implemented a fix, generating new CRLs with the correct structure by April 5, 2024. The CA has since integrated linting into their CRL issuance process to prevent future occurrences.

Model: gpt-4o-mini Generated: 2026-06-13 21:34 UTC Revised: 2026-06-16 18:12 UTC Confidence: 0.85 14 comments
Chronology
  1. Incident published regarding CRL compliance issue.
  2. New CRLs generated with correct structure.
  3. Linting for CRL issuing process implemented.
Thread Activity
  1. Google representative — Reported CRLs violating TLS BRs due to incorrect revoked certificates field.
  2. Assecods representative — Acknowledged the incident and committed to submitting an incident report.
  3. Assecods representative — No updates on the bug.
  4. Assecods representative — Confirmed implementation of linting for CRL issuing process.
Participants
Community commenter
Similar Local Cases
#1904494 RESOLVED Ca Certificate Compliance Ca Documents Audit Document Remediation Tracking Opened 2024-06-25 · Closed 2024-09-04 · 91% similar
Asseco DS / Certum: Cross-certificate not included in 2024 S/MIME Audit statement
#1909203 RESOLVED Ca Certificate Compliance Incident Opened 2024-07-22 · Closed 2025-05-13 · 90% similar
Asseco DS / Certum: CP/CPS, Revocation Requests Mechanism, Certificate Problem Report, CRL and OCSP disruption
#1889217 RESOLVED Incident Opened 2024-04-02 · Closed 2024-07-01 · 84% similar
Entrust: CRL non-conformance with the TLS BRs
#1495518 RESOLVED Ca Certificate Compliance Opened 2018-10-01 · Closed 2023-02-22 · 83% similar
Asseco DS / Certum: Unallowed key usage for EC public key (Key Encipherment)
#1879845 RESOLVED Ca Certificate Compliance Opened 2024-02-12 · Closed 2024-10-02 · 82% similar
Asseco DS / Certum: S/MIME certificates with error in subjectAlternativeName
#1409766 RESOLVED Ca Certificate Compliance Self Reported Incident Certificate Misissuance Opened 2017-10-18 · Closed 2023-02-22 · 81% similar
Asseco DS / Certum: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record
#1433118 RESOLVED Ca Certificate Compliance Opened 2018-01-25 · Closed 2022-11-14 · 80% similar
Asseco DS / Certum: certificate issued by Certum with compromised private key not revoked (windows10.microdone.cn)
#1917571 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2024-09-09 · Closed 2024-11-06 · 80% similar
Asseco DS / Certum: Organization Identifier and Country field discrepancies

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action