Asseco DS / Certum: WebTrust audit finding — S/MIME mailbox validation older than 30 days
During a WebTrust onsite audit on 06 March 2026, auditors identified a potential issue with the email verification process used for Certum-issued S/MIME certificates. Certum’s internal verification confirmed non-compliance with the requirement that validation of control of a mailbox SHALL be obtained no more than 30 days prior to certificate issuance for a subset of certificates. Certum reported that 181 S/MIME certificates were affected in total, and stated that all affected certificates were revoked and subscribers were informed and instructed on certificate replacement. Certum applied changes to its issuance system to enforce the 30-day validation requirement and re-evaluated validation data for certification requests already in progress, requiring revalidation where the allowed period was exceeded. The incident report also notes that an initial impact assessment missed some affected certificates due to an incorrectly defined filtering condition, and that additional affected certificates were discovered after the initial revocation window elapsed. Certum later reported completion of action items, including configuring dedicated S/MIME validation parameters, creating a registry/checklist of Baseline Requirements with numeric and time-based constraints, and introducing production acceptance tests; the bug is resolved as FIXED.
- Certum began issuing S/MIME certificates under S/MIME Baseline Requirements version 1.0.0.
- WebTrust auditors identified a potential issue with the S/MIME email verification period during an onsite audit.
- Certum revoked the initially identified non-compliant S/MIME certificates and verified CRLs.
- Certum identified additional affected certificates during secondary investigation and completed verification.
- Certum submitted the report closure summary and requested closure of the incident report.
- Assecods representative — Opened a preliminary incident report stating that WebTrust audit findings confirmed non-compliance with the 30-day mailbox validation requirement for certain S/MIME certificates, affecting 101 certificates, which were revoked and followed by subscriber notification and issuance-system changes.
- Assecods representative — Reported that extended analysis found additional affected certificates and that a separate incident for delayed revocation was opened (linked to bug 2023190).
- Assecods representative — Posted the full incident report with updated counts (181 affected total), described the cause (validation component validity parameter misconfiguration and insufficient review), and stated that all affected certificates were revoked and issuance was corrected to enforce the 30-day requirement.
- Assecods representative — Provided an action-items update showing completed configuration and registry work, with a planned next update date for remaining items.
- Assecods representative — Updated action items again, stating all action items were completed and that the closure report was scheduled for publication by 2026-04-23.
- Assecods representative — Submitted the report closure summary, including remediation steps (issuance configuration fix, re-evaluation of in-progress requests, and revocation of all affected certificates) and requested closure.
- CCADB representative — Posted a final call for comments and noted the bug would be closed on approximately 2026-04-30.