Asseco DS / Certum: CRL non-conformance with the TLS BRs
Asseco Data Systems S.A. disclosed a compliance issue regarding their Certificate Revocation Lists (CRLs), which were found to violate the TLS Baseline Requirements (BRs) and RFC 5280. Specifically, 49 CRLs contained the revoked certificates field without any revoked certificates present. The issue was detected through manual investigation and the use of the pkilint tool. Following the discovery, Asseco initiated an incident report and implemented a fix, generating new CRLs with the correct structure by April 5, 2024. The CA has since integrated linting into their CRL issuance process to prevent future occurrences.
- Incident published regarding CRL compliance issue.
- New CRLs generated with correct structure.
- Linting for CRL issuing process implemented.
- Google representative — Reported CRLs violating TLS BRs due to incorrect revoked certificates field.
- Assecods representative — Acknowledged the incident and committed to submitting an incident report.
- Assecods representative — No updates on the bug.
- Assecods representative — Confirmed implementation of linting for CRL issuing process.