← Asseco Data Systems S.A. cases
Bugzilla #1935393 Policy Compliance

Asseco DS / Certum: Failure to Update Policy Documents within 365 Days

RESOLVED FIXED Asseco Data Systems S.A.
AI Summary

Asseco Data Systems S.A. (Certum) failed to update its Certification Policy within the required 365 days, as mandated by the Baseline Requirements and Mozilla Root Store Policy. The issue was identified during a routine review of the CCADB, where it was discovered that the current policy was outdated. Although the incident did not affect certificate issuance, it highlighted gaps in internal procedures and reliance on individual methods for document updates. Certum has since revised its procedures, created an internal tracking system, and implemented a script to monitor policy updates, ensuring compliance moving forward.

Model: gpt-4o-mini Generated: 2026-06-13 21:35 UTC Confidence: 0.90
Chronology
  1. Certum Certification Policy v.5.0 was published.
  2. Policy review identified outdated Certification Policy.
  3. Incident reported on Bugzilla.
  4. Certification Policy v.5.1 was released.
  5. Procedure for documentation update was revised.
  6. Implementation of tracking script completed.
  7. Incident report closure summary provided.
Participants
Kateryna Aleksieieva
External References
Similar Local Cases
#1518560 RESOLVED Policy Compliance Opened 2019-01-08 · Closed 2023-02-22 · 51% similar
Asseco DS / Certum: Use of forbidden subjectPublicKeyInfo algorithm
#1717034 RESOLVED Policy Compliance Opened 2021-06-17 · Closed 2023-02-22 · 49% similar
Asseco DS / Certum: CPS does not refer to BR domain validation methods
#1815355 RESOLVED Policy Compliance Opened 2023-02-07 · Closed 2023-08-16 · 48% similar
Asseco DS / Certum: Cross-Signed non-EV-audited root with an EV-enabled root
#1769222 RESOLVED Policy Compliance Opened 2022-05-13 · Closed 2024-06-30 · 46% similar
SECOM: Failed an annual CPS update of Cybertrust Japan (CTJ)
#1817023 RESOLVED Policy Compliance Opened 2023-02-15 · Closed 2024-05-09 · 44% similar
Microsoft PKI Services: Failure to modify policy documents within 365 days
#1693930 RESOLVED Policy Compliance Opened 2021-02-20 · Closed 2023-02-22 · 43% similar
Microsoft PKI Services: Policy Documentation, Failure to update Subscriber Certificate Max Validity Period
#1542082 RESOLVED Policy Compliance Opened 2019-04-04 · Closed 2023-02-22 · 43% similar
IdenTrust: Failure to disclose Unconstrained intermediate Within 7 Days
#2025917 RESOLVED Policy Compliance Opened 2026-03-24 · Closed 2026-05-18 · 42% similar
IdenTrust: Full Incident Report for bug 2016585 was not published within 14 days of discovering the issue

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action