SECOM: Non-BR-Compliant Certificate Issuance
This case involves SECOM Trust Systems CO., LTD. disclosing non-compliance issues related to the issuance of certificates that did not meet the CA/Browser Forum's Baseline Requirements. The CA was made aware of the problems through discussions in the mozilla.dev.security.policy forum and this Bugzilla entry. SECOM confirmed it has ceased issuing the problematic certificates and provided a list of affected certificates. They also outlined steps to prevent future occurrences, including implementing technical measures to automate checks that were previously reliant on human verification. The resolution was marked as fixed on October 24, 2017, after the necessary changes were implemented.
- Initial report of non-compliance issues discovered by SECOM.
- SECOM confirmed the implementation of technical measures to prevent future issues.
- Mozilla representative — Outlined the compliance issues and requested a response from SECOM.
- Secom representative — Acknowledged the notice and stated they would contact customers and implement technical measures.
- Secom representative — Informed that the treatment was released today.
- Fastly representative — Marked the issue as resolved, indicating all actions were completed.