← SECOM Trust Systems CO., LTD. cases
Bugzilla #1560234
Certificate Problem Report
SECOM: Ambiguity on KeyUsage with ECC public key
RESOLVED
INVALID
SECOM Trust Systems CO., LTD.
AI Summary
SECOM Trust Systems identified an ambiguity regarding the KeyUsage extension in ECDSA certificates, which they initially believed constituted a misissuance. After a self-audit revealed 31 valid certificates with this issue, SECOM took proactive measures to revoke them and issued a corrected intermediate CA certificate. The ambiguity stemmed from RFC interpretations, and SECOM engaged with the community to address this issue. The case was ultimately resolved as invalid due to the recognized ambiguity in the RFCs.
Chronology
- Self-audit revealed 31 valid certificates with KeyUsage issues.
- Issued corrected intermediate CA certificate and stopped issuing problematic certificates.
- Revoked remaining certificates with KeyUsage problems.
Participants
Hisashi Kamo
Wayne Thayer
Jinta Nakamura
Ryan Sleevi
External References
Similar Local Cases
SECOM: certificate for which “L” and “ST” not set
SECOM: certificate for which “OU=-”
SECOM: Outdated audit statements for intermediate certificates
SECOM: Incorrect OCSP Delegated Responder Certificate
SECOM: certificate for .test TLD
SECOM: failure to revoke underscores
SECOM: FUJIFILM intermediate CA Certificate not listed in audit statement
SECOM: Insufficient Serial Number Entropy