← SECOM Trust Systems CO., LTD. cases
Bugzilla #1652610
Delayed Revocation
SECOM: Delayed Revocation of CA Certificate with OCSP EKU Issue
RESOLVED
FIXED
SECOM Trust Systems CO., LTD.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
This case addresses SECOM Trust Systems' failure to revoke an intermediate CA certificate within the required timeframe due to an OCSP EKU issue. The issue was initially reported in Bug 1649962, prompting discussions on the delays and SECOM's remediation plans. SECOM outlined a detailed schedule for certificate renewal and key destruction, with a commitment to improve their revocation processes. The CA has since completed the key destruction and provided documentation from their auditor, KPMG, confirming compliance. The case is now resolved.
Chronology
- Bug opened to track delayed revocation incident.
- Key destruction for old intermediate CAs completed.
Thread Activity
- Mozilla representative — Opening this bug to track incident report and discussion related to failure to revoke ICA within 7 days for OCSP EKU issue raised in bug 1649962.
- Secom representative — Here is the witness with our auditor KPMG. The minutes of key destruction authorized by 2 members of KPMG is attached.
Participants
Community commenter
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
SECOM: No updated CRLs published for Cybertrust Japan SureMail CA G4
SECOM: failure to revoke underscores
SECOM: Delayed Revocation of non-technically constrained FUJIFILM Certificates
Entrust: Late Revocation due to SHA-256 hash algorithm
Entrust: Late Revocation for SSL Certificates issued with Un-verified IP Addresses
Telekom Security: CRL also contained unrevoked certificates
CFCA: Delayed reporting of revocation of an intermediate CA certificate
CFCA: CRL Error