← SECOM Trust Systems CO., LTD. cases
Bugzilla #1560234 Self Reported Incident

SECOM: Ambiguity on KeyUsage with ECC public key

RESOLVED INVALID SECOM Trust Systems CO., LTD.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

SECOM reported a problem they discovered during a self-audit involving ECDSA certificates whose Key Usage included “key encipherment” and “data encryption,” which SECOM stated does not make sense. SECOM said the issue was found on 2019/02/05, and that 31 valid certificates were identified as having the problem. After discussion, SECOM decided to revoke the certificates by CA discretion on 2019/02/08, and they issued an intermediate CA certificate on 2019/03/15 that corrected the Key Usage; SECOM also stated that issuance of the problematic certificates was stopped at that time. SECOM reported revoking the affected certificates (30 between 2019/03/15 and 2019/04/24, and the remaining 4 on 2019/05/08), then revoking the intermediate CA certificate on 2019/05/13. SECOM also posted a question to the mozilla.dev.security.policy forum and stated that the RFC ambiguity was acknowledged, with an Internet Draft being proposed to correct the relevant RFC text. In the thread, reviewers agreed the appropriate Bugzilla resolution was RESOLVED INVALID, and SECOM later reported a Zlint GitHub issue for detection improvements at https://github.com/zmap/zlint/issues/291. The bug is currently marked RESOLVED with resolution INVALID.

Model: gpt-5.4-nano Generated: 2026-06-13 18:15 UTC Revised: 2026-06-16 18:43 UTC Confidence: 0.86 6 comments
Chronology
  1. SECOM self-audit identified 31 valid ECDSA certificates with Key Usage values SECOM considered inappropriate.
  2. SECOM issued an intermediate CA certificate correcting the Key Usage and stopped issuing the problematic certificates.
  3. SECOM revoked the intermediate CA certificate after revoking all affected end-entity certificates.
Thread Activity
  1. Secom representative — Hisashi Kamo described the self-audit findings, SECOM’s revocation and reissuance actions, and noted the RFC ambiguity discussion and related links.
  2. Fastly representative — Wayne Thayer asked whether SECOM modified its linting tool and whether changes were submitted to Zlint maintainers.
  3. Secom representative — Jinta Nakamura responded that an IETF document is being proposed, that SECOM had not reported to linting maintainers yet due to lack of consensus, and that SECOM’s linting tools (cablint, certlint, x509lint) detected the issue.
  4. Fastly representative — Wayne Thayer agreed the case should be RESOLVED INVALID and asked if there were further comments or questions.
  5. Community commenter — Ryan Sleevi agreed and praised SECOM’s proactive identification, unilateral revocation, and community engagement to resolve the ambiguity.
  6. Secom representative — Jinta Nakamura stated SECOM reported the issue to Zlint’s GitHub and provided the link to the Zlint issue.
Participants
Secom representative Fastly representative Community commenter
Similar Local Cases
#1391064 RESOLVED Self Reported Incident Incident Closure Request Opened 2017-08-16 · Closed 2023-02-22 · 100% similar
SECOM: Non-BR-Compliant Certificate Issuance
#1544712 RESOLVED Self Reported Incident Opened 2019-04-16 · Closed 2023-02-22 · 100% similar
SECOM: certificate for which “OU=-”
#1548714 RESOLVED Self Reported Incident Opened 2019-05-02 · Closed 2023-02-22 · 100% similar
SECOM: "Default City" in Subject:localityName
#1563574 RESOLVED Self Reported Incident Opened 2019-07-04 · Closed 2023-02-22 · 100% similar
SECOM: Failure to disclose Unconstrained Intermediate within 7 Days
#1398259 RESOLVED Self Reported Incident Incident Closure Request Opened 2017-09-08 · Closed 2023-02-22 · 96% similar
SECOM: Non-BR-Compliant OCSP Responders
#1497703 RESOLVED Self Reported Incident Certificate Misissuance Closure Request Opened 2018-10-09 · Closed 2023-02-22 · 96% similar
SECOM: Undisclosed intermediate certificates
#1524452 RESOLVED Self Reported Incident Opened 2019-02-01 · Closed 2023-02-22 · 95% similar
SECOM: certificate for .test TLD
#1544722 RESOLVED Self Reported Incident Opened 2019-04-16 · Closed 2023-02-22 · 81% similar
SECOM: certificate for which “L” and “ST” not set

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action