SECOM delayed revocation of non-technically constrained FUJIFILM certificates
SECOM reported that it learned on 2021-04-16, in connection with Bug 1695786, that FUJIFILM EE certificates issued before 2021-03-09 did not meet the requirements for a technically constrained sub-CA and needed revocation. SECOM said the revocation deadline was five days from that date, but the revocation was delayed while it coordinated with FUJIFILM. SECOM later stated that all relevant server certificates were revoked on 2021-04-26, covering 127 certificates issued between 2018-04-23 and 2021-03-08. Mozilla participants pressed SECOM for a concrete remediation plan and updates, and SECOM responded with plans for automation and a move toward non-public CA issuance for FUJIFILM. SECOM later reported that it created a non-public CA for Fujifilm, that it is not chained to a root trusted in the root store, that it has been tested and is in operation, and that no other remediation steps remain. The bug is marked RESOLVED with resolution FIXED.
- SECOM identified FUJIFILM EE certificates that needed revocation because they did not meet technically constrained sub-CA requirements.
- SECOM said all relevant FUJIFILM server certificates were revoked.
- SECOM said operation of the Fujifilm non-public CA started.
- SECOM said the Fujifilm non-public CA was created, tested, in operation, and that no other remediation steps remained.
- Secom representative — SECOM filed an incident report saying it recognized the revocation need on 2021-04-16, that revocation was delayed, and that 127 certificates were in scope.
- Secom representative — SECOM said all relevant server certificates were revoked on 2021-04-26 and described coordination issues with FUJIFILM.
- Community commenter — Paul Steinberg criticized the delay and questioned SECOM's handling of revocation and CAA checks.
- Community commenter — Ryan Sleevi said the explanation was insufficient and asked for a concrete plan to prevent future delays.
- Secom representative — SECOM said it would take the comments seriously, prepare an improvement plan, and work with FUJIFILM on automation.
- Secom representative — SECOM said it would update the automation plan on 2021-07-15 and that it was discussing implementation with FUJIFILM management.
- Secom representative — SECOM said it would coordinate testing with FUJIFILM by the end of September and figure out a production deployment plan by the same deadline.
- Secom representative — SECOM said it was proceeding with automation and migration to non-public CA issuance for FUJIFILM.
- Secom representative — SECOM said it and FUJIFILM agreed on revocation timing targets and were considering using private TLS server certificates for most FUJIFILM Fnet CA - S2 certificates.
- Secom representative — SECOM posted a non-public CA construction plan with dates for agreement, construction, evaluation, and issuance start.
- Secom representative — SECOM said operation of the non-public CA had started on 2022-03-07.
- Secom representative — SECOM confirmed the non-public CA was created, not chained to a trusted root, tested, in operation, and that no other remediation steps remained.
- Mozilla representative — Mozilla said it would close the bug on 2022-04-27 unless there were additional issues.