← Cybertrust Japan / JCSI cases
Bugzilla #1827490
Certificate Problem Report
Cybertrust Japan: CRL signature algorithm encoding error
RESOLVED
FIXED
Cybertrust Japan / JCSI
AI Summary
Cybertrust Japan faced an issue with the encoding of the signature algorithm in their Certificate Revocation Lists (CRLs). The inner and outer AlgorithmIdentifiers for the ecdsa-with-SHA384 algorithm were found to be non-compliant, leading to a request for an incident report. The CA took prompt action to investigate and remediate the issue, successfully publishing corrected CRLs. The problem was reported by CRL Watch, and the CA has since confirmed that the errors have been resolved.
Chronology
- CRL Watch reported encoding errors in Cybertrust Japan's CRLs.
- Remediated CRLs were published.
Participants
Ben Wilson
Masahiro Shikutani
Masaru Sakamoto
External References
Similar Local Cases
Cybertrust Japan: Root CRLs exceed maximum validity period by one second
SECOM: No updated CRLs published for Cybertrust Japan SureMail CA G4
DigiCert: 4 CRLs unavailable or not responding
SECOM: Cybertrust Japan's CRL lacks the critical flag in the issuingDistributionPoint extension
SECOM: S/MIME CA Modified Opinion Report of Cybertrust Japan (CTJ)
GoDaddy: Failure to revoke certificate with compromised key within 24 hours
Hongkong Post: Delayed response to CPR
DigiCert: Some CRLs were not updated for a few days