Asseco DS / Certum: Irregularities in Xinchacha/Xcc Brand SSL Certificates
The bug was opened by an external reporter who alleged irregularities related to Xinchacha/Xcc brand SSL certificates and suspected entities including “Xinchacha” and its affiliate “Zhongyu Yongxin.” The reporter referenced a video and contract materials and questioned whether OV certificate issuance was performed without strict organization identity verification. Certum responded that it is the sole Registration Authority for publicly trusted TLS certificates it issues, that resellers do not participate in validation decisions, and that Certum validates organization identity and Subject Information using documentation including results from independent and authoritative sources, with domain control verified using BR-approved methods. Certum stated it reviewed the validation materials related to the referenced OV certificate and did not identify irregularities in organization or authorization validation, and that the available information did not meet the criteria for an incident under the Baseline Requirements or CCADB policy. The CCADB incident reporting account later asked whether the issue should be closed as Invalid, and the bug was ultimately marked as INVALID and resolved. No further updates were provided after Certum’s initial response.
- A third party submitted a report alleging irregularities in OV SSL certificate issuance related to Xinchacha/Xcc brand certificates.
- Certum began a verification process in response to the report.
- Certum provided context on its validation model and stated it found no irregularities in the referenced OV certificate’s validation materials.
- The issue was proposed for closure as invalid and then marked INVALID.
- Community commenter — Reported suspected irregularities involving Xinchacha/Xcc brand SSL certificates and cited Certum OV validation requirements and referenced materials.
- Assecods representative — Thanked the reporter and stated Certum had started the verification process, with an update to follow.
- Assecods representative — Explained Certum’s validation model and stated it reviewed validation materials for the referenced OV certificate and did not identify irregularities; offered to reassess if verifiable evidence is provided.
- Assecods representative — Stated there were no updates on the issue.
- CCADB representative — Asked the broader community whether the incident should be closed as Invalid.
- Sectigo — Noted Sectigo’s name was mentioned and suggested actions such as re-auditing materials and revoking certificates with potential forgery materials.
- Assecods representative — Proposed closing the issue as invalid.
- CCADB representative — Marked the bug as invalid.