← Asseco Data Systems S.A. cases
Bugzilla #2021685 Self Reported Incident

Asseco DS / Certum: WebTrust audit finding — S/MIME mailbox validation older than 30 days

RESOLVED FIXED Asseco Data Systems S.A.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

During a WebTrust onsite audit on 06 March 2026, auditors identified a potential issue with the email verification process used for Certum-issued S/MIME certificates. Certum’s internal verification confirmed non-compliance with the requirement that validation of control of a mailbox SHALL be obtained no more than 30 days prior to certificate issuance for a subset of certificates. Certum reported that 181 S/MIME certificates were affected in total, and stated that all affected certificates were revoked and subscribers were informed and instructed on certificate replacement. Certum applied changes to its issuance system to enforce the 30-day validation requirement and re-evaluated validation data for certification requests already in progress, requiring revalidation where the allowed period was exceeded. The incident report also notes that an initial impact assessment missed some affected certificates due to an incorrectly defined filtering condition, and that additional affected certificates were discovered after the initial revocation window elapsed. Certum later reported completion of action items, including configuring dedicated S/MIME validation parameters, creating a registry/checklist of Baseline Requirements with numeric and time-based constraints, and introducing production acceptance tests; the bug is resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:37 UTC Revised: 2026-06-16 18:14 UTC Confidence: 0.90 9 comments
Chronology
  1. Certum began issuing S/MIME certificates under S/MIME Baseline Requirements version 1.0.0.
  2. WebTrust auditors identified a potential issue with the S/MIME email verification period during an onsite audit.
  3. Certum revoked the initially identified non-compliant S/MIME certificates and verified CRLs.
  4. Certum identified additional affected certificates during secondary investigation and completed verification.
  5. Certum submitted the report closure summary and requested closure of the incident report.
Thread Activity
  1. Assecods representative — Opened a preliminary incident report stating that WebTrust audit findings confirmed non-compliance with the 30-day mailbox validation requirement for certain S/MIME certificates, affecting 101 certificates, which were revoked and followed by subscriber notification and issuance-system changes.
  2. Assecods representative — Reported that extended analysis found additional affected certificates and that a separate incident for delayed revocation was opened (linked to bug 2023190).
  3. Assecods representative — Posted the full incident report with updated counts (181 affected total), described the cause (validation component validity parameter misconfiguration and insufficient review), and stated that all affected certificates were revoked and issuance was corrected to enforce the 30-day requirement.
  4. Assecods representative — Provided an action-items update showing completed configuration and registry work, with a planned next update date for remaining items.
  5. Assecods representative — Updated action items again, stating all action items were completed and that the closure report was scheduled for publication by 2026-04-23.
  6. Assecods representative — Submitted the report closure summary, including remediation steps (issuance configuration fix, re-evaluation of in-progress requests, and revocation of all affected certificates) and requested closure.
  7. CCADB representative — Posted a final call for comments and noted the bug would be closed on approximately 2026-04-30.
Participants
Assecods representative CCADB representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1832093 RESOLVED Self Reported Incident Certificate Misissuance Opened 2023-05-09 · Closed 2023-06-02 · 82% similar
Asseco DS / Certum: Subordinate certificates with sequential serial number
#2044023 RESOLVED Certificate Misissuance Self Reported Incident Remediation Tracking Opened By Ca Opened 2026-06-01 · Closed 2026-07-02 · 81% similar
Asseco DS / Certum: Cross-Certificates subject encoding discrepancy
#1409766 RESOLVED Ca Certificate Compliance Self Reported Incident Certificate Misissuance Opened 2017-10-18 · Closed 2023-02-22 · 81% similar
Asseco DS / Certum: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record
#1511459 RESOLVED Self Reported Incident Opened 2018-11-30 · Closed 2023-02-22 · 81% similar
Asseco DS / Certum: Corrupted certificates
#1611458 RESOLVED Self Reported Incident Opened 2020-01-24 · Closed 2023-02-22 · 80% similar
Asseco DS / Certum: Invalid value in SAN dNSName
#1567062 RESOLVED Self Reported Incident Audit Finding Opened 2019-07-18 · Closed 2023-02-22 · 79% similar
Asseco DS / Certum: inconsistent disclosure of externally-operated intermediate
#1667684 RESOLVED Self Reported Incident Opened 2020-09-27 · Closed 2023-02-22 · 79% similar
Asseco DS / Certum: Failure to provide a preliminary report within 24 hours.
#1709392 RESOLVED Self Reported Incident Certificate Misissuance Opened 2021-05-04 · Closed 2023-02-22 · 79% similar
Asseco DS / Certum: Invalid stateOrProvinceName field (recurrent incident)

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action