Asseco DS / Certum: Incomplete CRL Disclosure in CCADB
The bug reports that Certum’s CCADB disclosure of CRL URLs for the “Certum Trusted Network CA” root was incomplete. A third party notified Certum that the CCADB field “JSON Array of All Full CRL URLs” contained only http://crl.certum.pl/ctnca.crl, while certificates associated with this CA included additional CRL Distribution Point URLs. The additional CRL Distribution Point URLs were functional and redirected to the same CRL file as the URL disclosed in CCADB, but the CCADB record did not include all CRL URLs present in the certificates. The thread states this was a violation of Section 6.2 of the CCADB Policy. Certum says it is correcting the discrepancy and verifying whether similar incomplete disclosures affect other CA records, with a full incident report planned no later than 2026-07-31. The bug is currently marked as ASSIGNED.
- Certum was notified by a third party that CCADB CRL URL disclosure for the Certum Trusted Network CA root was incomplete.
- Assecods representative — Posted a preliminary incident report stating the CCADB “JSON Array of All Full CRL URLs” was incomplete versus the CRL Distribution Point URLs in certificates, citing a Section 6.2 CCADB Policy violation, and describing planned correction and verification.