← Asseco Data Systems S.A. cases
Bugzilla #1917571
Certificate Problem Report
Asseco DS / Certum: Organization Identifier and Country field discrepancies
RESOLVED
FIXED
Asseco Data Systems S.A.
AI Summary
Asseco Data Systems S.A. reported discrepancies in the Organization Identifier and Country fields for four S/MIME certificates. The issue was identified during a routine scan, revealing that two certificates had already been revoked prior to the discovery. The root causes included limitations in the initial validation process and confusion over similar country names. To address these issues, improvements were made to the validation mechanisms and user interface, including the addition of ISO Country Codes. All mis-issued certificates were revoked, and the incident has been resolved.
Chronology
- BR for S/MIME certificates came into force.
- Incident created after mis-issuance was confirmed.
- Three mis-issued certificates revoked.
- Addition of ISO Country Code in user interface completed.
- Case marked as resolved.
Participants
Kateryna Aleksieieva
External References
Similar Local Cases
Asseco DS / Certum: Finding in Routine WebTrust Audit – S/MIME certificates issued with mailbox validation older than 30 days
Asseco DS / Certum: CRL non-conformance with the TLS BRs
Asseco DS / Certum: Cross-certificate not included in 2024 S/MIME Audit statement
Asseco DS / Certum: DNS service outage
Asseco DS / Certum: CRL URLs disclosed in CCADB do not exactly match the CRL URLs in certificates
Asseco DS / Certum: Irregularities in Xinchacha/Xcc Brand SSL Certificates
Asseco DS / Certum: CP/CPS, Revocation Requests Mechanism, Certificate Problem Report, CRL and OCSP disruption
Asseco DS / Certum: Invalid stateOrProvinceName field (recurrent incident)