← Cybertrust Japan / JCSI cases
Bugzilla #1769222 Incident

SECOM: Failed an annual CPS update of Cybertrust Japan (CTJ)

RESOLVED FIXED Cybertrust Japan / JCSI
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Cybertrust Japan (CTJ), a subordinate CA signed by Security Communication RootCA2 (SECOM), identified that its CPS annual update was overdue. The issue was discovered during review of a draft next CPS update (version 1.3) and CPs, and CTJ stated that the CPS last update was April 1, 2021 (version 1.2) and CPs last update was November 30, 2021. CTJ reported the incident to its Policy Authority (PA), informed SECOM Trust Systems, and submitted an incident report for SECOM’s review. CTJ stated that certificate issuance was not stopped because the issue did not result in misissuance of certificates. As remediation, CTJ strengthened annual assessment procedures by transferring management of periodic annual assessments to the PA’s task (with the PA developing and executing the plan) and reviewing schedule/status at monthly PA meetings; SECOM also began managing and checking subordinate CAs’ CPs/CPSes revision status and notifying them before exceeding renewal deadlines. In later comments, the CA team stated that the monthly PA review and SECOM’s constant checking were working properly and that no additional remediation steps were planned. The bug was resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:20 UTC Revised: 2026-06-16 18:29 UTC Confidence: 0.86 7 comments
Chronology
  1. CTJ published CPS version 1.2 (CPS last update).
  2. CTJ published CPs with last update date of November 30, 2021.
  3. CTJ identified the overdue CPS annual update and began informing its Policy Authority and SECOM Trust Systems.
  4. CTJ completed CPS update (version 1.3).
  5. CTJ and SECOM provided remediation steps in comment #7 of the incident report.
  6. Mozilla indicated it would close the bug on or about July 15, 2022.
Thread Activity
  1. Secom representative — Hisashi Kamo (SECOM) submitted an incident report stating CTJ identified the overdue annual CPS update and provided a timeline and remediation overview.
  2. Secom representative — Kamo asked for time to prepare section #7 of the incident report.
  3. Secom representative — Kamo provided remediation steps: CTJ strengthened annual assessment procedures by moving periodic annual assessment management to the PA task and SECOM began managing/checking subordinate CPs/CPSes revision status.
  4. Mozilla representative — Ben Wilson asked what other remediation steps, if any, were planned.
  5. Secom representative — Kamo stated the remediation was working properly and that no additional steps were planned.
  6. Secom representative — Kamo reiterated that monthly PA review at CTJ and SECOM’s checking were working properly and that there were no other remediation steps related to the bug.
  7. Mozilla representative — Ben Wilson said he would close the bug on or about Friday, 15-Jul-2022.
Participants
Secom representative Mozilla representative
External References
Similar Local Cases
#1950574 RESOLVED Ca Certificate Compliance Incident Revocation Issue Opened 2025-02-26 · Closed 2025-09-15 · 88% similar
SECOM: S/MIME CA Modified Opinion Report of Cybertrust Japan (CTJ)
#1735998 RESOLVED Incident Opened 2021-10-15 · Closed 2023-02-22 · 74% similar
SECOM: Root CRLs exceed maximum validity period by 1 second
#1731164 RESOLVED Incident Opened 2021-09-16 · Closed 2023-02-22 · 71% similar
Google Trust Services: CRL validity period set to expected value plus one second
#1931413 RESOLVED Incident Opened 2024-11-14 · Closed 2024-12-27 · 69% similar
Google Trust Services: New hire onboarding deviation from written procedure
#1846216 RESOLVED Incident Opened 2023-07-31 · Closed 2023-09-29 · 69% similar
Disig: Failure to Respond to Jun 2023 Apple Root Program Survey
#1742704 RESOLVED Incident Self Reported Incident Opened 2021-11-23 · Closed 2024-05-09 · 68% similar
Let's Encrypt: Potential Denial of Service against websites with broad private key reuse
#1891039 RESOLVED Incident Opened 2024-04-11 · Closed 2024-05-05 · 68% similar
Sectigo: Premature disabling of CRL generation for an inactive CA
#1848240 RESOLVED Ca Certificate Compliance Incident Remediation Tracking Opened 2023-08-10 · Closed 2023-11-02 · 68% similar
TWCA: Undisclosed CA

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action