← Asseco Data Systems S.A. cases
Bugzilla #2023190
Delayed Revocation
Asseco DS / Certum: Delayed revocation of S/MIME certificates issued with mailbox validation older than 30 days
RESOLVED
FIXED
Asseco Data Systems S.A.
AI Summary
Asseco Data Systems S.A. (Certum) faced a delayed revocation issue concerning 32 S/MIME certificates that were not revoked within the required timeframe due to an incomplete initial impact assessment. This oversight was identified during an internal audit, leading to the revocation of the affected certificates. The incident stemmed from incorrect assumptions about the verification process and inadequate filtering logic in the search script. Certum has since updated its procedures to enhance impact assessment validation and prevent future occurrences.
Chronology
- Certum confirmed the issue and initiated a mass revocation procedure.
- Additional non-compliant certificates were identified.
- Revocation of the additionally identified certificates was completed.
- Closure report planned to be published.
Participants
Kateryna Aleksieieva
External References
Similar Local Cases
Asseco DS / Certum: Delayed revocation of SHECA cross certificate
Asseco DS / Certum: Delayed revocation of SSL.COM cross certificate
SSL.com: Delayed revocation of 53 certificates affected by bug #1750631
HARICA: delayed revocation for bug 1943596
Entrust: Late Revocation due to SHA-256 hash algorithm
Entrust: Delayed Revocation for EV TLS Certificate incorrect jurisdiction
D-Trust: Delay beyond 5 days in revoking misissued certificate
HARICA: Delayed revocation for non-BR-compliant CA Certificates within 7 days