SECOM: Undisclosed intermediate certificates
This case concerns SECOM Trust Systems CO., LTD. failing to disclose certain intermediate certificates within one week of issuance, as required by Mozilla policy section 5.3.2. The issue was raised in the bug by Wayne Thayer (Fastly), who pointed to two crt.sh entries marked with the mozilladisclosure option and asked SECOM to provide an incident report. SECOM responded that it failed to disclose due to a “misrecognition,” and stated that it disclosed the certificates on CCADB after receiving the bug notice. SECOM later provided an incident report explaining that, during CCADB registration for a code signing certificate in August, it received a message that registration was unnecessary, and it then mixed up that guidance for the certificates in this case. SECOM said it updated its manual for the key ceremony to include the CCADB disclosure procedure and provided education to operational staff to prevent similar misrecognition. The bug was marked RESOLVED with resolution FIXED.
- SECOM’s intermediate certificates were issued without being disclosed to CCADB within the required one-week timeframe.
- SECOM received notice of the disclosure failure and subsequently disclosed the certificates on CCADB.
- SECOM submitted an incident report describing the cause and remediation steps.
- SECOM clarified that it misunderstood a prior CCADB-related message about whether disclosure was necessary.
- Community commenter — Wayne Thayer reported that SECOM failed to disclose the specified intermediate certificates within one week and requested an incident report per Mozilla’s misissuance incident report guidance, including posting to the mozilla.dev.security.policy forum.
- Community commenter — Hisashi Kamo thanked Wayne Thayer and stated that due to misrecognition SECOM failed to disclose, and that it disclosed the certificates.
- Community commenter — Wayne Thayer asked SECOM to provide an incident report explaining why the problem happened and how SECOM would prevent recurrence.
- Community commenter — Hisashi Kamo provided an incident report stating SECOM became aware via the bug email, disclosed on CCADB after receiving it, and attributed the failure to misrecognition during CCADB registration guidance in August; he also described updating key ceremony documentation and training operational staff.
- Community commenter — Wayne Thayer asked for more detail on what SECOM meant by “misrecognition” and confirmed whether CCADB disclosure was added to the standard key ceremony procedure documentation.
- Community commenter — Hisashi Kamo explained that SECOM misunderstood a message about technical constraints and disclosure necessity, and confirmed that CCADB disclosure was added to the key ceremony procedure documentation.