← SECOM Trust Systems CO., LTD. cases
Bugzilla #1897346 Certificate Problem Report

SECOM: Difference in upper and lower case between CN field and SAN

RESOLVED FIXED SECOM Trust Systems CO., LTD.
AI Summary

SECOM Trust Systems identified a misissuance involving 24 TLS server-authentication certificates where the Subject's commonName did not match the dNSName byte-for-byte, although they matched case-insensitively. Initially, SECOM believed this did not violate Baseline Requirements until they received clarification from the Chrome Root Program on May 15, 2024, acknowledging it as a misissuance. SECOM revoked 37 affected certificates by May 20, 2024, and has since implemented zlint as a pre-linting tool to prevent future occurrences. They now interpret the Baseline Requirements to require a case-sensitive match between the commonName and dNSName.

Model: gpt-4o-mini Generated: 2026-06-13 21:09 UTC Confidence: 0.90
Chronology
  1. Baseline Requirements Ver.1.8.0 became effective.
  2. SECOM implemented zlint in their system.
  3. SECOM contacted Chrome Root Program regarding potential misissuance.
  4. SECOM confirmed misissuance based on Chrome's criteria.
  5. SECOM completed revocation of 37 certificates.
Participants
SECOM Trust Systems - ONO Fumiaki clintw@apple.com amir@aaomidi.com rdaurne77@gmail.com mathew.hodson@gmail.com corey.bonnell@digicert.com bwilson@mozilla.com
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
#1950574 RESOLVED Certificate Problem Report Opened 2025-02-26 · Closed 2025-09-15 · 66% similar
SECOM: S/MIME CA Modified Opinion Report of Cybertrust Japan (CTJ)
#1886110 RESOLVED Certificate Problem Report Opened 2024-03-19 · Closed 2025-02-14 · 63% similar
TWCA: Revocation delay for TLS certificates with non-critical basicConstraints
#1897630 RESOLVED Certificate Problem Report Opened 2024-05-19 · Closed 2024-08-15 · 62% similar
Entrust: Jurisdiction issue in some EV TLS & Code Signing certificates
#1905419 RESOLVED Certificate Problem Report Opened 2024-06-28 · Closed 2024-10-31 · 62% similar
GoDaddy: Intermittent unauthorized OCSP response when certificate is freshly issued
#1885754 RESOLVED Certificate Problem Report Opened 2024-03-16 · Closed 2024-09-13 · 61% similar
Entrust: CPR was not responded to in 24 hours
#1931515 RESOLVED Certificate Problem Report Opened 2024-11-15 · Closed 2025-01-06 · 60% similar
SECOM: Issuance of TLS server certificates using keys previously compromised
#1986911 RESOLVED Certificate Problem Report Opened 2025-09-04 · Closed 2025-10-22 · 58% similar
SECOM: No updated CRLs published for Cybertrust Japan SureMail CA G4
#2004654 RESOLVED Certificate Problem Report Opened 2025-12-08 · Closed 2026-02-12 · 58% similar
SECOM: Invalid stateOrProvinceName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action