← SECOM Trust Systems CO., LTD. cases
Bugzilla #1695993
Certificate Problem Report
SECOM: Outdated audit statements for intermediate certificates
RESOLVED
FIXED
SECOM Trust Systems CO., LTD.
AI Summary
SECOM Trust Systems CO., LTD. faced issues with outdated audit statements for two intermediate certificates, which were past their audit period. The certificates were revoked on March 9, 2021, after being flagged for not having their SHA-256 fingerprints included in the audit reports. An incident report was requested to explain the oversight, leading to discussions about the root causes and the processes in place for audits. SECOM has since revised its procedures to ensure all intermediate certificates are subject to audits, regardless of their usage status.
Chronology
- Audit statements for intermediate certificates identified as outdated.
- The two intermediate certificates were revoked.
- Discussion on closing the bug case initiated.
Participants
Kathleen Wilson
Hisashi Kamo
Ryan Sleevi
Fumiaki Ono
External References
Similar Local Cases
SECOM: FUJIFILM intermediate CA Certificate not listed in audit statement
SECOM: Non-BR-Compliant OCSP Responders
SECOM: certificate for which “L” and “ST” not set
SECOM: Insufficient Serial Number Entropy
SECOM: Ambiguity on KeyUsage with ECC public key
SECOM: Incorrect OCSP Delegated Responder Certificate
SECOM: certificate for which “OU=-”
SECOM: certificate for .test TLD