Asseco DS / Certum: Cross-certificate omitted from 2024 S/MIME audit statement
Asseco Data Systems S.A. (Certum) reported that one cross-certificate was unintentionally omitted from its 2024 S/MIME audit statement, which caused an ALV check-up failure in CCADB. The company said the issue did not affect certificate issuance. It explained that the omission came from a lapse in the audit compilation and verification process, where the CA list was manually compiled and not cross-referenced accurately against the audit report. Mozilla asked whether the auditor/CAB could re-issue the S/MIME 2024 audit statement with the cross-certificate included. The CA said it was working with the auditor on re-issuance, later reported that a verification script had been created and tested, and Mozilla indicated it intended to close the bug.
- CA certificate list for the audit was prepared.
- S/MIME 2024 audit statement was issued.
- Audit was submitted to CCADB after ALV check-up.
- Certum identified the missing cross-certificate issue.
- Bug was opened to report the omitted cross-certificate.
- Additional verification script for audit reports was created and tested.
- Assecods representative — Reported that a cross-certificate was unintentionally omitted from the S/MIME 2024 Audit statement and that this caused an ALV check-up failure in CCADB.
- Mozilla representative — Asked whether the auditor/CAB could re-issue the S/MIME 2024 Audit statement with the cross-certificate included.
- Assecods representative — Said the team was working on re-issuance and had been asked to report the case on Bugzilla.
- Assecods representative — Filed the incident report, described the root cause, and listed an action item to automate CA list generation for audit reports.
- Assecods representative — Reported that a verification script had been created and tested and marked the automation action item completed.
- Mozilla representative — Stated an intention to close the bug on or about 2024-08-30.
- Assecods representative — Asked Mozilla to close the bug since there had been no further questions or updates.