SECOM: Outdated audit statements for intermediate certificates
This case concerns SECOM Trust Systems’ intermediate certificates whose audit statements were past due. The reporter identified two intermediate certificates (JPRS Organization Validation Authority - G3 and JPRS Domain Validation Authority - G3) whose Standard Audit Period End Date and BR Audit Period End Date were 10/29/2019, and noted that SECOM had provided audit statements for the doppelgangers but not for these specific certificate fingerprints. SECOM stated that the two particular intermediate certificates were revoked on March 9, 2021. SECOM also provided an incident report describing how it became aware of the issue via the Bugzilla report, a timeline of issuance (July 10, 2020) and revocation, and why the certificates were not included in the audit scope (SECOM said it had decided not to use them). SECOM revised its manuals and check sheets to prevent recurrence and described process changes involving tracking intermediate CA certificates and treating all JPRS intermediate CA certificates as subject to audit. The bug was scheduled for closure by Mozilla after SECOM’s responses.
- SECOM issued two intermediate certificates later identified as having outdated/missing audit statements.
- SECOM became aware of the issue after a Bugzilla report was posted.
- SECOM revoked the two intermediate certificates in question.
- Mozilla scheduled the bug for closure (unless additional matters were raised).
- Mozilla representative — Reported that audit statements were past due for two specific intermediate certificate fingerprints and suggested revocation.
- Community commenter — Pointed to Bug 1695938 as also concerning.
- Secom representative — Confirmed the two intermediate certificates were revoked on March 9.
- Mozilla representative — Requested an incident report explaining why the specific SHA-256 fingerprints were not listed in the audit reports, including a link to Mozilla’s incident-report guidance.
- Secom representative — Provided an incident report with a timeline, stated the CA had stopped/issued revocation, summarized the problematic certificates, and described steps to revise manuals and check sheets.
- Community commenter — Asked for more technical detail, including the serial number entropy issue, why revocation was not immediate, and what changed in the process.
- Ml representative — Submitted an incident-report correction and additional explanation from SECOM regarding the serial number digit issue and revocation timing.
- Ml representative — Corrected an omission in the revocation-planning description and referenced related bugs.
- Mozilla representative — Indicated the bug could be closed and scheduled closure for 16-Apr-2021 unless additional matters were discussed.