Asseco Data Systems / Certum: Delayed revocation of additional S/MIME certificates due to incomplete impact assessment
This case concerns Certum S/MIME certificates whose revocation was delayed. During internal investigation and remediation of Bug 2021685, Certum identified additional S/MIME certificates affected by the same underlying e-mail verification non-compliance, but these were omitted from the initial impact assessment scope due to an incorrectly defined filtering condition in the original search script. An onsite audit on 06 March 2026 identified the issue with the e-mail verification process, and Certum confirmed non-compliance after internal verification. Certum revoked the initially identified certificates and later identified 32 additional certificates that remained valid and required revocation; these were revoked in a separate revocation event scheduled for 2026-03-12. The report closure summary states that the search script was corrected and revalidated, and incident handling procedures were updated to validate the completeness of impact assessments, including edge cases and verification of the applied search methodology. The bug is resolved as FIXED, with action items completed and a closure report planned to be published by April 10, 2026.
- Certum confirmed the e-mail verification issue and initiated a mass revocation procedure for initially identified affected S/MIME certificates.
- Certum identified an additional, more complex impact scenario while preparing the report for Bug 2021685.
- Certum revoked 32 additionally identified S/MIME certificates that had not been revoked within the required 24-hour timeframe.
- Certum published the report closure summary stating remediation steps were completed and requested closure.
- Assecods representative — Certum provided a preliminary incident report stating that additional affected S/MIME certificates were identified during investigation of Bug 2021685 and were revoked, with a full incident report to be published by 27 March 2026.
- Assecods representative — Certum submitted the full incident report describing onsite audit findings, the omission of 61 affected certificates from the initial scope, and revocation of 32 additionally affected certificates in a separate event.
- Assecods representative — Certum stated it would continue monitoring and had no further updates, with closure report planned by April 10, 2026.
- Assecods representative — Certum reported closure details, including correction and revalidation of the search script and updated incident handling procedures, and requested closure of the report.
- CCADB representative — CCADB requested final comments or questions before the incident report would be closed approximately 2026-04-18.