← Asseco Data Systems S.A. cases
Bugzilla #2002281 Ca Certificate Compliance

Asseco DS / Certum: Irregularities in Xinchacha/Xcc Brand SSL Certificates

RESOLVED INVALID Asseco Data Systems S.A.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The bug was opened by an external reporter who alleged irregularities related to Xinchacha/Xcc brand SSL certificates and suspected entities including “Xinchacha” and its affiliate “Zhongyu Yongxin.” The reporter referenced a video and contract materials and questioned whether OV certificate issuance was performed without strict organization identity verification. Certum responded that it is the sole Registration Authority for publicly trusted TLS certificates it issues, that resellers do not participate in validation decisions, and that Certum validates organization identity and Subject Information using documentation including results from independent and authoritative sources, with domain control verified using BR-approved methods. Certum stated it reviewed the validation materials related to the referenced OV certificate and did not identify irregularities in organization or authorization validation, and that the available information did not meet the criteria for an incident under the Baseline Requirements or CCADB policy. The CCADB incident reporting account later asked whether the issue should be closed as Invalid, and the bug was ultimately marked as INVALID and resolved. No further updates were provided after Certum’s initial response.

Model: gpt-5.4-nano Generated: 2026-06-13 21:36 UTC Revised: 2026-06-16 18:14 UTC Confidence: 0.90 10 comments
Chronology
  1. A third party submitted a report alleging irregularities in OV SSL certificate issuance related to Xinchacha/Xcc brand certificates.
  2. Certum began a verification process in response to the report.
  3. Certum provided context on its validation model and stated it found no irregularities in the referenced OV certificate’s validation materials.
  4. The issue was proposed for closure as invalid and then marked INVALID.
Thread Activity
  1. Community commenter — Reported suspected irregularities involving Xinchacha/Xcc brand SSL certificates and cited Certum OV validation requirements and referenced materials.
  2. Assecods representative — Thanked the reporter and stated Certum had started the verification process, with an update to follow.
  3. Assecods representative — Explained Certum’s validation model and stated it reviewed validation materials for the referenced OV certificate and did not identify irregularities; offered to reassess if verifiable evidence is provided.
  4. Assecods representative — Stated there were no updates on the issue.
  5. CCADB representative — Asked the broader community whether the incident should be closed as Invalid.
  6. Sectigo — Noted Sectigo’s name was mentioned and suggested actions such as re-auditing materials and revoking certificates with potential forgery materials.
  7. Assecods representative — Proposed closing the issue as invalid.
  8. CCADB representative — Marked the bug as invalid.
Participants
Community commenter Assecods representative Asseco Data Systems S.A. CCADB representative Sectigo
Similar Local Cases
#2007105 RESOLVED Ca Certificate Compliance Opened 2025-12-19 · Closed 2026-03-30 · 95% similar
Asseco DS / Certum: CRL URLs disclosed in CCADB do not exactly match the CRL URLs in certificates
#1909203 RESOLVED Ca Certificate Compliance Incident Opened 2024-07-22 · Closed 2025-05-13 · 75% similar
Asseco DS / Certum: CP/CPS, Revocation Requests Mechanism, Certificate Problem Report, CRL and OCSP disruption
#1917571 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2024-09-09 · Closed 2024-11-06 · 74% similar
Asseco DS / Certum: Organization Identifier and Country field discrepancies
#1904494 RESOLVED Ca Certificate Compliance Ca Documents Audit Document Remediation Tracking Opened 2024-06-25 · Closed 2024-09-04 · 73% similar
Asseco DS / Certum: Cross-certificate not included in 2024 S/MIME Audit statement
#1451228 RESOLVED Ca Certificate Compliance Opened 2018-04-04 · Closed 2023-02-22 · 70% similar
Asseco DS / Certum: EV certificate mis-issue
#2032485 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2026-04-16 · Closed 2026-05-04 · 67% similar
DigiCert: Misissuance detected by PKIMetal
#1409766 RESOLVED Ca Certificate Compliance Self Reported Incident Certificate Misissuance Opened 2017-10-18 · Closed 2023-02-22 · 67% similar
Asseco DS / Certum: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record
#1435770 RESOLVED Ca Certificate Compliance Opened 2018-02-05 · Closed 2023-02-22 · 67% similar
Asseco DS / Certum: Non-BR-Compliant Issuance - Debian Weak Keys

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action