← Cybertrust Japan / JCSI cases
Bugzilla #1737242
Certificate Problem Report
Cybertrust Japan: Root CRLs exceed maximum validity period by one second
RESOLVED
FIXED
Cybertrust Japan / JCSI
AI Summary
Cybertrust Japan identified an issue where four of their root Certificate Revocation Lists (CRLs) had a validity period of 365 days plus one second, violating the Baseline Requirements. The problem was discovered on October 20, 2021, and corrective actions were taken, including the issuance of new CRLs on October 22. A full incident report was prepared and posted on October 26, detailing the steps taken to address the issue and prevent future occurrences. No subscriber certificates were impacted by this issue.
Chronology
- Identified CRL validity issue
- Issued corrected CRLs
- Posted full incident report
Participants
Masaru Sakamoto
Ben Wilson
External References
Similar Local Cases
Cybertrust Japan: CRL signature algorithm encoding error
SECOM: No updated CRLs published for Cybertrust Japan SureMail CA G4
SECOM: Cybertrust Japan's CRL lacks the critical flag in the issuingDistributionPoint extension
Certigna: Certificate issued with validity period greater than 398-days
DigiCert: 4 CRLs unavailable or not responding
SECOM: Root CRLs exceed maximum validity period by 1 second
Camerfirma: Invalid authorityKeyIdentifier - recurrent incident
SECOM: S/MIME CA Modified Opinion Report of Cybertrust Japan (CTJ)