← SECOM Trust Systems CO., LTD. cases
Bugzilla #1563574
Certificate Misissuance
SECOM: Failure to disclose Unconstrained Intermediate within 7 Days
RESOLVED
FIXED
SECOM Trust Systems CO., LTD.
AI Summary
SECOM Trust Systems CO., LTD. failed to disclose an unconstrained intermediate certificate within the required 7-day period, violating Mozilla's policy. The issue was identified through a Bugzilla report, leading to an investigation that revealed the intermediate certificate did not meet the necessary technical constraints. SECOM acknowledged the oversight, revoked the problematic certificates, and committed to improving their processes to prevent future occurrences. An incident report was submitted detailing the timeline of events and corrective actions taken.
Chronology
- Bugzilla report received, issue identified.
- SECOM stopped issuing certificates from the problematic intermediate CAs.
- SECOM revoked the two intermediate CA certificates.
- SECOM proposed a revised workflow to prevent future issues.
Participants
Ryan Sleevi
Hisashi Kamo
Yuu Hidaka
Jinta Nakamura
Wayne Thayer
External References
Similar Local Cases
SECOM: "Default City" in Subject:localityName
SECOM: Mis-issued EV Certificates
SECOM: Undisclosed intermediate certificates
SECOM: Unqualified domain name in SAN
SECOM: TSA Certs Issued from Root
SECOM: CrossTrust: OU > 64 characters
Telia: Failure to disclose Unconstrained Intermediate within 7 Days
certSIGN: "Some-State" in stateOrProvinceName