← Asseco Data Systems S.A. cases
Bugzilla #2061178 Ca Certificate Compliance Externally Reported Incident Certificate Misissuance Validation Issue Remediation Tracking

Asseco Data Systems / Certum: incorrect subject geographic data in certificates; expanded review raised affected population to 143 and remediation is complete

ASSIGNED Asseco Data Systems S.A.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns Certum certificates that contained incorrect subject geographic information, starting with an incorrect country value and later including other address fields such as state, locality, street address, and postal code. The case was opened after Certum received a Certificate Problem Report and confirmed the reported issue, then revoked the affected certificate. Certum’s investigation found that its address verification workflow could accept incorrect data when supporting sources returned inconsistent or inconclusive results. After Chrome Root Program staff identified an additional affected certificate, Certum re-evaluated the scope and expanded the incident from 29 affected certificates to 143 affected certificates, including TLS, code signing, and S/MIME certificates. Certum said the permanent system remediation was deployed on 2026-09-03 and that the final review and updated Full Incident Report were completed on 2026-09-16. The thread now reflects that all identified affected certificates were revoked or otherwise no longer valid, and no remaining valid certificates were reported.

Model: gpt-5.4-mini Generated: 2026-08-10 11:44 UTC Revised: 2026-09-20 07:00 UTC Confidence: 0.97 14 comments
Chronology
  1. The earliest affected certificate identified in the incident was issued.
  2. Certum received a Certificate Problem Report about an incorrect subject country value and confirmed the issue.
  3. Certum revoked the additional mis-issued certificates identified in its initial investigation.
  4. Chrome Root Program staff identified an additional active certificate with a geographic inconsistency.
  5. Certum deployed permanent remediation for the address validation workflow.
  6. Certum published an updated Full Incident Report with the expanded scope and final action-item status.
Thread Activity
  1. Assecods representative — Certum said it received a Problem Report about an incorrect Country value, revoked the certificate, and was preparing a full incident report.
  2. Assecods representative — Certum reported 29 affected certificates and described the address-validation weakness and planned remediation.
  3. Google representative — Chrome Root Program staff said the assessment scope appeared incomplete and asked Certum to explain its methodology and whether it would re-evaluate its active certificate corpus.
  4. Assecods representative — Certum said it had revoked the additional certificate and would provide a detailed response to the scope questions.
  5. Assecods representative — Certum explained the initial scope assessment and said it would re-evaluate the active certificate corpus and update the incident report.
  6. Assecods representative — Certum marked the internal validation-procedure update as complete.
  7. Assecods representative — Certum said the permanent remediation had been deployed and that it was performing the final review before the updated report.
  8. Assecods representative — Certum marked the self-audit procedure update as complete.
  9. Assecods representative — Certum updated the Full Incident Report, expanding the affected population to 143 certificates and closing out the final action-item status.
Participants
Assecods representative Google representative
Similar Local Cases
#1600301 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-11-29 · Closed 2023-02-22 · 82% similar
Asseco DS / Certum: EV Certificates issued with wrong Business Category
#2044023 RESOLVED Certificate Misissuance Self Reported Incident Remediation Tracking Opened By Ca Opened 2026-06-01 · Closed 2026-07-02 · 81% similar
Asseco DS / Certum: Cross-Certificates subject encoding discrepancy
#1409764 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-10-18 · Closed 2023-02-22 · 79% similar
Asseco DS / Certum: CAA mis-issuance on critical flag and unknown CAA tag
#1420860 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-11-27 · Closed 2023-02-22 · 79% similar
Asseco DS / Certum: CAA Mis-Issuance on mix of wildcard and non-wildcard DNS names in SAN
#2056087 RESOLVED Ca Certificate Compliance Incident Externally Reported Incident Certificate Misissuance Opened 2026-07-19 · Closed 2026-09-14 · 78% similar
Disig: CP/CPS misstatement regarding Key Usage criticality for TLS certificates
#1823040 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2023-03-17 · Closed 2023-05-19 · 78% similar
Asseco DS / Certum: Cross-certificate with wrong policy identifier
#1435770 RESOLVED Ca Certificate Compliance Opened 2018-02-05 · Closed 2023-02-22 · 72% similar
Asseco DS / Certum: Non-BR-Compliant Issuance - Debian Weak Keys
#1445857 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2018-03-15 · Closed 2023-02-22 · 71% similar
DigiCert: Mis-issuance of certificate with https in CN/SAN

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

⚠

Confirm action