Asseco Data Systems / Certum: incorrect subject geographic data in certificates; expanded review raised affected population to 143 and remediation is complete
This case concerns Certum certificates that contained incorrect subject geographic information, starting with an incorrect country value and later including other address fields such as state, locality, street address, and postal code. The case was opened after Certum received a Certificate Problem Report and confirmed the reported issue, then revoked the affected certificate. Certum’s investigation found that its address verification workflow could accept incorrect data when supporting sources returned inconsistent or inconclusive results. After Chrome Root Program staff identified an additional affected certificate, Certum re-evaluated the scope and expanded the incident from 29 affected certificates to 143 affected certificates, including TLS, code signing, and S/MIME certificates. Certum said the permanent system remediation was deployed on 2026-09-03 and that the final review and updated Full Incident Report were completed on 2026-09-16. The thread now reflects that all identified affected certificates were revoked or otherwise no longer valid, and no remaining valid certificates were reported.
- The earliest affected certificate identified in the incident was issued.
- Certum received a Certificate Problem Report about an incorrect subject country value and confirmed the issue.
- Certum revoked the additional mis-issued certificates identified in its initial investigation.
- Chrome Root Program staff identified an additional active certificate with a geographic inconsistency.
- Certum deployed permanent remediation for the address validation workflow.
- Certum published an updated Full Incident Report with the expanded scope and final action-item status.
- Assecods representative — Certum said it received a Problem Report about an incorrect Country value, revoked the certificate, and was preparing a full incident report.
- Assecods representative — Certum reported 29 affected certificates and described the address-validation weakness and planned remediation.
- Google representative — Chrome Root Program staff said the assessment scope appeared incomplete and asked Certum to explain its methodology and whether it would re-evaluate its active certificate corpus.
- Assecods representative — Certum said it had revoked the additional certificate and would provide a detailed response to the scope questions.
- Assecods representative — Certum explained the initial scope assessment and said it would re-evaluate the active certificate corpus and update the incident report.
- Assecods representative — Certum marked the internal validation-procedure update as complete.
- Assecods representative — Certum said the permanent remediation had been deployed and that it was performing the final review before the updated report.
- Assecods representative — Certum marked the self-audit procedure update as complete.
- Assecods representative — Certum updated the Full Incident Report, expanding the affected population to 143 certificates and closing out the final action-item status.