← Asseco Data Systems S.A. cases
Bugzilla #2044023
Certificate Problem Report
Asseco DS / Certum: Cross-Certificates subject encoding discrepancy
ASSIGNED
Asseco Data Systems S.A.
AI Summary
On June 1, 2026, Certum identified a discrepancy involving two CRLs due to differences in the encoding of fields within the Subject of four cross-certificates issued for a new Single Purpose Root CA hierarchy. The issue was discovered during a routine review of CRL Watch entries. The non-compliance was identified on June 1 and resolved by June 8, 2026, with all affected certificates being revoked. The incident was attributed to a lack of attention to changes in the default encoding of CA certificate subject fields.
Chronology
- Non-compliance start date
- Non-compliance identified
- Non-compliance resolved
Participants
Wojciech Trapczyński
External References
Similar Local Cases
Asseco DS / Certum: commonName not from subjectAltName entries
Asseco DS / Certum: Corrupted certificates
Asseco DS / Certum: Cross-certificate with wrong policy identifier
Asseco DS / Certum: Subordinate certificates with sequential serial number
Asseco DS / Certum: Unallowed key usage for EC public key (Key Encipherment)
Asseco DS / Certum: Intermediate CA certificates not listed in audit report
Asseco DS / Certum: Failure to revoke intermediate certificates within the BR time period
Asseco DS / Certum: Failure to revoke within 5 days