← Cybertrust Japan / JCSI cases
Bugzilla #1827490 Self Reported Incident

Cybertrust Japan: CRL signature algorithm encoding error (ECDSA parameters mismatch)

RESOLVED FIXED Cybertrust Japan / JCSI
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

CRL Watch reported that two of Cybertrust Japan’s CRLs had a mismatch between the inner and outer AlgorithmIdentifier encodings for ECDSA with SHA-384: the inner AlgorithmIdentifier had no parameters while the outer AlgorithmIdentifier included parameters specifying the named curve "secp384r1". Mozilla requested that Cybertrust Japan file an incident report. Cybertrust Japan stated that Ben Wilson notified them of the CRL Watch errors and that they investigated the issue, confirmed the cause related to the required AlgorithmIdentifier encoding, and developed a patch. Cybertrust Japan reported that it received approval of its remediation plan from its PA and then remediated the CRLs, publishing corrected CRLs on 2023-04-11 15:37 JST and confirming the errors were removed from CRL Watch. The CA also stated it had not issued subscriber certificates yet under the affected CAs. The bug is marked RESOLVED with resolution FIXED, and Mozilla indicated it intended to close the bug after monitoring showed no further incidents.

Model: gpt-5.4-nano Generated: 2026-06-13 21:23 UTC Revised: 2026-06-16 18:34 UTC Confidence: 0.86 10 comments
Chronology
  1. CRL Watch reported encoding errors in two Cybertrust Japan CRLs involving mismatched inner/outer ECDSA signature AlgorithmIdentifier parameters.
  2. Cybertrust Japan published remediated CRLs with corrected signature algorithm encoding and confirmed the errors were removed from CRL Watch.
Thread Activity
  1. Mozilla representative — Explained that the outer AlgorithmIdentifier parameters were non-compliant and stated the CRLs were fixed, requesting Cybertrust Japan file an incident report.
  2. SECOM Trust Systems CO., LTD. — Provided the incident report describing how they became aware via CRL Watch, their investigation timeline, remediation steps, and that remediated CRLs were published and errors removed from CRL Watch.
  3. SECOM Trust Systems CO., LTD. — Stated they were monitoring the bug.
  4. SECOM Trust Systems CO., LTD. — Commented on behalf of Masahiro that they were monitoring the bug.
  5. SECOM Trust Systems CO., LTD. — Stated they were monitoring the bug.
  6. SECOM Trust Systems CO., LTD. — Stated they were monitoring the bug.
  7. SECOM Trust Systems CO., LTD. — Stated they were monitoring the bug.
  8. SECOM Trust Systems CO., LTD. — Stated they were monitoring the bug.
  9. SECOM Trust Systems CO., LTD. — Stated they were monitoring the bug.
  10. Mozilla representative — Said they had not noticed further incidents while monitoring CRL Watch and intended to close the bug around 2-June-2023.
Participants
Mozilla representative SECOM Trust Systems CO., LTD. Community commenter
Similar Local Cases
#2007070 RESOLVED Self Reported Incident Certificate Misissuance Revocation Issue Opened 2025-12-19 · Closed 2026-03-30 · 80% similar
SECOM: Non conformant SCT Encoding Due to SCT Modification by Cybertrust Japan (CTJ)
#2021550 RESOLVED Self Reported Incident Revocation Issue Opened 2026-03-06 · Closed 2026-03-26 · 80% similar
SECOM: 2025 S/MIME CA Modified Opinion Report of Cybertrust Japan (CTJ)
#1975624 RESOLVED Self Reported Incident Opened 2025-07-04 · Closed 2025-09-24 · 79% similar
SECOM: Cybertrust Japan's CRL lacks the critical flag in the issuingDistributionPoint extension
#1752670 RESOLVED Certificate Misissuance Self Reported Incident Opened 2022-01-29 · Closed 2024-05-09 · 77% similar
Let's Encrypt: TLS Using ALPN Allows Additional Identifiers in Challenge Certificate
#1671410 RESOLVED Self Reported Incident Opened 2020-10-15 · Closed 2024-06-30 · 73% similar
IdenTrust: Inconsistent Disclosure of Externally-Operated Intermediate
#1689589 RESOLVED Self Reported Incident Security Incident Opened 2021-01-29 · Closed 2023-02-22 · 70% similar
Telia: Disallowed curve (P-521) in leaf certificate
#1942651 RESOLVED Self Reported Incident Policy Document Issue Opened 2025-01-20 · Closed 2025-02-14 · 70% similar
Sectigo / SSL.com: Late disclosure of updated SSL.com CP/CPS to CCADB
#1676440 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-11-10 · Closed 2023-02-22 · 70% similar
NetLock: Cumulative report connected to EV verification

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action