← Asseco Data Systems S.A. cases
Bugzilla #2023190 Delayed Revocation

Asseco DS / Certum: Delayed revocation of S/MIME certificates issued with mailbox validation older than 30 days

RESOLVED FIXED Asseco Data Systems S.A.
AI Summary

Asseco Data Systems S.A. (Certum) faced a delayed revocation issue concerning 32 S/MIME certificates that were not revoked within the required timeframe due to an incomplete initial impact assessment. This oversight was identified during an internal audit, leading to the revocation of the affected certificates. The incident stemmed from incorrect assumptions about the verification process and inadequate filtering logic in the search script. Certum has since updated its procedures to enhance impact assessment validation and prevent future occurrences.

Model: gpt-4o-mini Generated: 2026-06-13 21:37 UTC Confidence: 0.90
Chronology
  1. Certum confirmed the issue and initiated a mass revocation procedure.
  2. Additional non-compliant certificates were identified.
  3. Revocation of the additionally identified certificates was completed.
  4. Closure report planned to be published.
Participants
Kateryna Aleksieieva
Related Bugzilla IDs Mentioned
Similar Local Cases
#1825734 RESOLVED Delayed Revocation Opened 2023-03-31 · Closed 2023-06-01 · 51% similar
Asseco DS / Certum: Delayed revocation of SHECA cross certificate
#1826363 RESOLVED Delayed Revocation Opened 2023-04-04 · Closed 2023-06-08 · 50% similar
Asseco DS / Certum: Delayed revocation of SSL.COM cross certificate
#1752636 RESOLVED Delayed Revocation Opened 2022-01-28 · Closed 2023-02-22 · 47% similar
SSL.com: Delayed revocation of 53 certificates affected by bug #1750631
#1945389 RESOLVED Delayed Revocation Opened 2025-02-02 · Closed 2025-05-01 · 42% similar
HARICA: delayed revocation for bug 1943596
#1651481 RESOLVED Delayed Revocation Opened 2020-07-08 · Closed 2023-02-22 · 42% similar
Entrust: Late Revocation due to SHA-256 hash algorithm
#1804753 RESOLVED Delayed Revocation Opened 2022-12-08 · Closed 2023-04-19 · 42% similar
Entrust: Delayed Revocation for EV TLS Certificate incorrect jurisdiction
#1862082 RESOLVED Delayed Revocation Opened 2023-10-30 · Closed 2023-12-14 · 42% similar
D-Trust: Delay beyond 5 days in revoking misissued certificate
#1651465 RESOLVED Delayed Revocation Opened 2020-07-08 · Closed 2023-02-22 · 41% similar
HARICA: Delayed revocation for non-BR-compliant CA Certificates within 7 days

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action