← SECOM Trust Systems CO., LTD. cases
Bugzilla #1563574
Self Reported Incident
SECOM: Failure to disclose Unconstrained Intermediate within 7 Days
RESOLVED
FIXED
SECOM Trust Systems CO., LTD.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
SECOM Trust Systems CO., LTD. failed to disclose an unconstrained intermediate certificate within the required 7-day timeframe, as mandated by Mozilla's policy. The issue was identified by an external party, leading to a request for an incident report. SECOM acknowledged the oversight, confirmed that the intermediate certificate did not meet the necessary technical constraints, and subsequently revoked the affected certificates. The CA committed to implementing procedural changes to prevent future occurrences and submitted an incident report detailing the timeline and corrective actions taken.
Chronology
- SECOM was notified of the failure to disclose an unconstrained intermediate certificate.
- SECOM revoked the affected intermediate and server certificates.
Thread Activity
- Community commenter — The following certificate has been issued and is not disclosed within CCADB.
- Secom representative — We are now summarizing the detailed information regarding this issue.
- Community commenter — The certificate is required to be disclosed and audited due to insufficient constraints.
- Secom representative — We found that the control of the name constraints is insufficient.
- Secom representative — We have revoked this certificate and signing CA certificate.
- Fastly representative — It appears that all questions have been answered and remediation is complete.
Participants
Community commenter
Secom representative
Fastly representative
External References
Similar Local Cases
SECOM: Non-BR-Compliant Certificate Issuance
SECOM: certificate for which “OU=-”
SECOM: "Default City" in Subject:localityName
SECOM: Ambiguity on KeyUsage with ECC public key
SECOM: Undisclosed intermediate certificates
SECOM: Non-BR-Compliant OCSP Responders
SECOM: certificate for .test TLD
SECOM: Incorrect OCSP Delegated Responder Certificate