Asseco DS / Certum: third-party reported CCADB non-compliance for six pre-inclusion Root CA records with unreachable CRL URLs; bug resolved
This case concerns six pre-inclusion Root CA records for Asseco Data Systems S.A. / Certum in CCADB that were configured with CRL Distribution Point URLs returning HTTP 404. The issue was first raised by a third party on 2026-06-26, and Certum later determined that the report was valid and that the configuration did not comply with CCADB requirements. Certum said the non-compliance began on 2024-08-31 and was corrected on 2026-07-06 by submitting an Add/Update Root Request to fix the CRL endpoint information. In its closure summary, Certum said it updated its onboarding procedure, held an internal review session, and completed all action items. CCADB incident reporting then posted a final call for comments on 2026-07-27, and the Bugzilla bug is now RESOLVED with resolution FIXED.
- An Add/Update Root Request adding six pre-inclusion Root CA records with unreachable CRL endpoints was closed.
- A third-party report was received about six Root CA records in CCADB whose CRL Distribution Point URLs returned HTTP 404.
- An Add/Update Root Request was submitted and closed to correct the unreachable CRL endpoint information.
- Assecods representative — Submitted a preliminary incident report describing the third-party report and saying no evidence of BR or CCADB non-compliance had yet been identified.
- Asseco Data Systems S.A. — Submitted the full incident report, said Certum determined the report was valid, and gave the CCADB policy basis and timeline.
- Asseco Data Systems S.A. — Said there were no updates on the bug.
- Asseco Data Systems S.A. — Posted a report closure summary stating the issue was corrected, remediation was completed, and closure was requested.
- CCADB representative — Posted a final call for comments and said the bug would be closed on approximately 2026-08-03.