← SECOM Trust Systems CO., LTD. cases
Bugzilla #1524452
Certificate Problem Report
SECOM: certificate for .test TLD
RESOLVED
FIXED
SECOM Trust Systems CO., LTD.
AI Summary
SECOM Trust Systems issued a certificate for a reserved TLD, .test, which included an invalid DNS SAN. The certificate was revoked on the same day it was issued, but an incident report was not filed at that time. After being prompted by Mozilla, SECOM prepared an incident report detailing the timeline of events and corrective actions taken to prevent future occurrences. They have since enhanced their review processes and implemented systematic validation for domain control.
Chronology
- SECOM issued and revoked a certificate for test20180323.secom.test.
- Issue was pointed out in Bugzilla.
- SECOM provided an incident report.
- System enhancements were implemented.
Participants
Andrew Ayer
Hisashi Kamo
Wayne Thayer
External References
Similar Local Cases
SECOM: failure to revoke underscores
SECOM: FUJIFILM intermediate CA Certificate not listed in audit statement
SECOM: certificate for which “L” and “ST” not set
SECOM: Ambiguity on KeyUsage with ECC public key
SECOM: Non-BR-Compliant OCSP Responders
SECOM: certificate for which “OU=-”
SECOM: Outdated audit statements for intermediate certificates
Collect the full set of URLs for all CRLs used by EV certs issued by SECOM Trust