Asseco Data Systems S.A. / Certum: Cross-certificates subject encoding discrepancy
Certum (Asseco Data Systems S.A.) reported an internal incident discovered on 2026-06-01 while reviewing CRL Watch entries. The investigation found that four cross-certificates issued for a dedicated TLS server authentication PKI hierarchy had Subject fields whose encoding was not byte-for-byte identical to the corresponding existing Root CA certificates, as required for cross-certified subordinate CA naming. Certum stated issuance was not stopped because the affected cross-certificates were generated offline. Certum implemented fixes to the cross-certificate profile configuration on 2026-06-03 to correct the Subject field encoding, then revoked the affected cross-certificates on 2026-06-08 and generated replacement cross-certificates with corrected Subject encoding. Certum also described corrective and preventive measures, including a dedicated issuance profile and updated procedures/checklists to validate Subject field encoding for cross-certificates. The thread includes a report closure summary requesting closure after action items were completed, and CCADB issued a final call for comments before closure on approximately 2026-07-02. The bug is marked RESOLVED with resolution FIXED.
- Four cross-certificates for the dedicated TLS server authentication PKI hierarchy were generated using cross-certificate profile configurations that produced Subject encoding discrepancies.
- Certum identified the Subject encoding discrepancy while reviewing CRL Watch entries.
- Certum fixed the cross-certificate profile configuration to correct Subject field encoding.
- Certum revoked the affected cross-certificates and generated replacement cross-certificates with corrected Subject field encoding.
- Asseco Data Systems S.A. — Submitted a preliminary incident report describing an internal discovery of CRL Watch discrepancies caused by differences in Subject field encoding in four cross-certificates.
- Asseco Data Systems S.A. — Submitted a full incident report with timeline, cited the CABF BR cross-certified subordinate naming requirement, and described fixes, revocation, and regeneration.
- Asseco Data Systems S.A. — Reported that there were no updates on the bug.
- Asseco Data Systems S.A. — Provided a report closure summary stating the affected cross-certificates were revoked and replaced, and requested closure after action items were completed.
- CCADB representative — Issued a final call for comments or questions and stated the incident report would be closed on approximately 2026-07-02.