← Cybertrust Japan / JCSI cases
Bugzilla #1737242 Other

Cybertrust Japan: Root CRLs exceed maximum validity period by one second

RESOLVED FIXED Cybertrust Japan / JCSI
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Cybertrust Japan reported a compliance issue affecting root CRLs: four current root CRLs had a validity period of 365 days plus one second. The CA stated this did not comply with BR section 4.9.7, which requires that the nextUpdate field must not be more than twelve months beyond the thisUpdate field. Cybertrust Japan said it identified the problem on October 20, 2021 by reviewing other CA incident reports, and it noted that certificate issuance was not stopped because the issue did not result in misissuance of certificates. The CA issued corrected CRLs on October 22, and it posted both a preliminary incident report (October 22) and a full incident report (October 26). The thread also states that impact was limited to root CRLs and that subscriber certificates were not impacted. The bug was resolved with resolution set to FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:19 UTC Revised: 2026-06-16 18:29 UTC Confidence: 0.50 5 comments
Chronology
  1. Cybertrust Japan identified that four root CRLs had nextUpdate values exceeding the BR 4.9.7 limit by one second.
  2. Cybertrust Japan issued corrected root CRLs to remediate the CRL validity period issue.
  3. Cybertrust Japan completed investigation and posted the full incident report.
Thread Activity
  1. SECOM Trust Systems CO., LTD. — Posted a preliminary incident report stating that four root CRLs had validity of 365 days plus one second and that corrected CRLs were being re-issued on October 22.
  2. SECOM Trust Systems CO., LTD. — Provided a full incident report describing how the issue was discovered, the timeline of actions, remediation steps (corrected CRLs), and stated that subscriber certificates were not impacted.
  3. SECOM Trust Systems CO., LTD. — Noted that Cybertrust Japan would monitor the bug for community questions.
  4. Mozilla representative — Asked whether there was any reason the bug could not be closed.
  5. Mozilla representative — Indicated Mozilla would close the bug sometime next week.
Participants
SECOM Trust Systems CO., LTD. Mozilla representative
External References
Similar Local Cases
#1827490 RESOLVED Self Reported Incident Opened 2023-04-11 · Closed 2023-06-02 · 42% similar
Cybertrust Japan: CRL signature algorithm encoding error
#1769222 RESOLVED Incident Opened 2022-05-13 · Closed 2024-06-30 · 35% similar
SECOM: Failed an annual CPS update of Cybertrust Japan (CTJ)

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action