← SECOM Trust Systems CO., LTD. cases
Bugzilla #1695786
Certificate Misissuance
SECOM: Unqualified domain name in SAN
RESOLVED
FIXED
SECOM Trust Systems CO., LTD.
AI Summary
SECOM Trust Systems CO., LTD. issued a certificate containing an unqualified domain name 'sgnwffw001' in the Subject Alternative Name (SAN) extension. This misissuance was identified on March 2, 2021, leading to the immediate revocation of the certificate. SECOM acknowledged the issue and committed to implementing corrective measures, including fixing the settings to prevent such occurrences in the future. The incident raised concerns regarding the adequacy of SECOM's domain validation processes and their understanding of the Baseline Requirements for Certificate Authorities.
Chronology
- Certificate issued with unqualified domain name in SAN.
- Certificate revoked after identification of the issue.
- Settings adjusted to limit FQDN in SAN.
- CAA records lookup failure handling function implemented.
Participants
George [:fozzie]
Hisashi Kamo
Ryan Sleevi
Paul Steinberg
External References
Similar Local Cases
SECOM: "Default City" in Subject:localityName
SECOM: Failure to disclose Unconstrained Intermediate within 7 Days
SECOM: Mis-issued EV Certificates
SECOM: TSA Certs Issued from Root
SECOM: Undisclosed intermediate certificates
SECOM: CrossTrust: OU > 64 characters
Microsoft PKI Services: Certificate Mis-Issuance, DNSNames must have a valid TLD
Sectigo: Failure to revoke within 5 days