← SECOM Trust Systems CO., LTD. cases
Bugzilla #1695938
Certificate Problem Report
SECOM: FUJIFILM intermediate CA Certificate not listed in audit statement
RESOLVED
FIXED
SECOM Trust Systems CO., LTD.
AI Summary
SECOM Trust Systems disclosed an intermediate CA certificate for FUJIFILM that was not included in the associated audit statement, raising concerns about compliance with Mozilla's requirements. The certificate was issued without name constraints, which led to significant operational failures and trust issues. SECOM acknowledged the problem and revoked the certificate on March 9, 2021. They provided an incident report detailing the timeline of events and the reasons for the oversight, including a corporate split that complicated communication and decision-making processes.
Chronology
- Initial report of the issue by Andrew Ayer.
- FUJIFILM intermediate CA certificate revoked.
- SECOM provided an incident report outlining the timeline and causes.
- Further clarifications on the audit oversight and compliance failures.
- Bug closed after monitoring.
Participants
Andrew Ayer
Hisashi Kamo
Ryan Sleevi
Ben Wilson
External References
Similar Local Cases
SECOM: certificate for .test TLD
SECOM: Outdated audit statements for intermediate certificates
SECOM: Incorrect OCSP Delegated Responder Certificate
Entrust root has SECOM CPS in AllCertificateRecordsCSVFormatv2
SECOM: certificate for which “L” and “ST” not set
SECOM: Root CRLs exceed maximum validity period by 1 second
SECOM: Insufficient Serial Number Entropy
SECOM: Ambiguity on KeyUsage with ECC public key