← Asseco Data Systems S.A. cases
Bugzilla #1958645 Ca Security Vulnerability

Asseco Data Systems (Certum): certum.pl DNS service outage (self-reported incident)

RESOLVED FIXED Asseco Data Systems S.A.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case documents a self-reported DNS service outage for the certum.pl domain that occurred between 16:30 on 2025-04-04 (CEST) and 02:00 on 2025-04-05 (CEST). The outage affected most services registered under certum.pl, including services related to SSL certificates, but did not affect the issuance of certificates. The CA stated the incident was discovered internally through system monitoring and later provided a full incident report. The CA reported that the outage was caused by a misconfiguration in DNS domain delegation, which resulted in DNS queries not being routed to the appropriate servers. The CA restored the delegation to the correct servers by 2025-04-04 23:54 UTC and reported that remediation included restructuring infrastructure tests from external locations and implementing a detailed test to prevent recurrence, as well as separating domain administration privileges between Certum and ADS. The CA published a report closure summary stating all planned improvements and action items were completed and requested closure of the incident. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:36 UTC Revised: 2026-06-16 18:13 UTC Confidence: 0.90 9 comments
Chronology
  1. certum.pl DNS service outage began due to a DNS delegation misconfiguration.
  2. DNS service was restored after delegation was corrected; certificate issuance was not affected.
  3. Domain transfer process was initiated to separate domain administration permissions at the registrar level.
  4. Transfer of the last domain was completed, finalizing the permission-separation action item.
  5. Report closure summary was published and closure was requested.
Thread Activity
  1. Assecods representative — Filed a preliminary incident report stating the outage was internally discovered via system monitoring and that a full report would follow by 2025-04-18.
  2. Asseco Data Systems S.A. — Submitted the full incident report with timeline, stated self-reported source of disclosure, described DNS delegation misconfiguration as the cause, and detailed remediation and policy impacts.
  3. Asseco Data Systems S.A. — Posted that there were no updates on the bug.
  4. Asseco Data Systems S.A. — Posted that there were no updates on the bug.
  5. Asseco Data Systems S.A. — Provided an update that domains would be transferred to a different registrar to achieve separation of domain management permissions, and requested a next-update flag.
  6. Asseco Data Systems S.A. — Reported that the transfer of the last domain was completed and that the final action item was finalized, requesting closure if no further comments.
  7. Asseco Data Systems S.A. — Published the report closure summary stating remediation steps were completed and requested closure of the incident.
  8. Assecods representative — Requested closure, stating all action items were completed and the closure summary had been published.
  9. CCADB representative — Issued a final call for comments and stated the incident would be closed on approximately 2025-06-10.
Participants
Assecods representative Asseco Data Systems S.A. CCADB representative
External References
Similar Local Cases
#2032511 RESOLVED Ca Security Vulnerability Self Reported Incident Opened 2026-04-16 · Closed 2026-05-29 · 69% similar
Google Trust Services: Short OCSP outage
#1909203 RESOLVED Ca Certificate Compliance Incident Opened 2024-07-22 · Closed 2025-05-13 · 65% similar
Asseco DS / Certum: CP/CPS, Revocation Requests Mechanism, Certificate Problem Report, CRL and OCSP disruption
#1917571 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2024-09-09 · Closed 2024-11-06 · 62% similar
Asseco DS / Certum: Organization Identifier and Country field discrepancies
#1878106 RESOLVED Ca Security Vulnerability Security Incident Opened 2024-02-01 · Closed 2024-03-08 · 61% similar
HARICA: Anomaly in OCSP services after CA software upgrade
#2021685 RESOLVED Self Reported Incident Opened 2026-03-07 · Closed 2026-04-30 · 61% similar
Asseco DS / Certum: Finding in Routine WebTrust Audit – S/MIME certificates issued with mailbox validation older than 30 days
#1662346 RESOLVED Ca Security Vulnerability Security Incident Opened 2020-09-01 · Closed 2023-02-22 · 60% similar
DigiCert: OCSP responder returning invalid responses
#1744795 RESOLVED Ca Security Vulnerability Security Incident Opened 2021-12-07 · Closed 2023-02-22 · 60% similar
DigiCert: Issuance of certs with weak keys (ROCA)
#1816806 RESOLVED Ca Security Vulnerability Security Incident Opened 2023-02-15 · Closed 2023-03-09 · 60% similar
DigiCert: OCSP not responding issue

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action