← SECOM Trust Systems CO., LTD. cases
Bugzilla #1897346 Certificate Misissuance Revocation Issue

SECOM incident report for CN/SAN case-mismatch certificates

RESOLVED FIXED SECOM Trust Systems CO., LTD.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

SECOM reported an incident involving 24 TLS server-authentication certificates whose subject commonName did not match the SAN dNSName byte-for-byte, though the values were case-insensitively equal. SECOM said it first learned of the issue from a reporter email on 2024-05-10 and initially believed the certificates were not violating the Baseline Requirements or current root programs. After receiving a reply from the Chrome Root Program on 2024-05-15, SECOM acknowledged the issue as mis-issuance under Chrome’s criteria and began its incident process. SECOM completed revocation of 37 certificates on 2024-05-20 and later stated that it now interprets BR section 7.1.4.3 as requiring a case-sensitive character-for-character match between commonName and SAN dNSName. The thread also records SECOM’s explanation of its linting history, including first-party pre-linting, zlint implementation on 2024-03-20, and later updates to action items and internal reporting practices. Mozilla indicated on 2024-07-18 that, since there were no remaining action items or questions, the bug was scheduled for closure.

Model: gpt-5.4-mini Generated: 2026-06-13 21:09 UTC Revised: 2026-06-16 18:52 UTC Confidence: 0.97 31 comments
Chronology
  1. SECOM was notified of 24 TLS certificates with CN/SAN case-mismatch issues.
  2. SECOM acknowledged the certificates as mis-issuance under Chrome Root Program criteria.
  3. SECOM completed revocation of 37 certificates.
  4. Mozilla stated the bug would be closed due to no remaining action items or questions.
Thread Activity
  1. Ml representative — SECOM opened the incident report and described 24 affected TLS certificates, its initial interpretation of the requirements, and its investigation into the CN/SAN mismatch.
  2. Apple representative — Clint Wilson said the wording still appeared to require case matching and questioned SECOM’s interpretation.
  3. Ml representative — SECOM said it completed revocation of 37 certificates and explained its pre-linting history and interpretation of the Baseline Requirements.
  4. Ml representative — SECOM confirmed it currently interprets BR 7.1.4.3 as requiring a case-sensitive character-for-character match.
  5. Ml representative — SECOM updated action items with dates for the oldest valid certificate, bug review, zlint implementation, mis-issuance confirmation, revocation deadline, and root cause analysis.
  6. Ml representative — SECOM added an action item to share its future mis-issuance reporting policy with members.
  7. Mozilla representative — Ben Wilson said there were no action items or questions left and scheduled the bug for closure.
Participants
Ml representative Apple representative Community commenter DigiCert Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1896596 RESOLVED Certificate Misissuance Revocation Issue Opened 2024-05-14 · Closed 2024-07-24 · 100% similar
SECOM: Certificates Issued with lower case value in subject:countryName
#1910322 RESOLVED Certificate Misissuance Revocation Issue Opened 2024-07-29 · Closed 2025-06-18 · 96% similar
DigiCert: Random value in CNAME without underscore prefix
#1890685 RESOLVED Revocation Issue Certificate Misissuance Opened 2024-04-09 · Closed 2025-02-21 · 94% similar
Entrust: Failure to revoke EV TLS certificates issued before CPS update
#1894054 RESOLVED Certificate Misissuance Revocation Issue Opened 2024-04-29 · Closed 2024-07-03 · 93% similar
SwissSign: MPKI step-up process sets wrong JoI Locality
#1645686 RESOLVED Certificate Misissuance Revocation Issue Opened 2020-06-14 · Closed 2023-02-22 · 93% similar
Sectigo: Lack of input validation in stateOrProvinceName
#2004654 RESOLVED Certificate Misissuance Opened 2025-12-08 · Closed 2026-02-12 · 89% similar
SECOM: Invalid stateOrProvinceName
#2021550 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2026-03-06 · Closed 2026-03-26 · 88% similar
SECOM: 2025 S/MIME CA Modified Opinion Report of Cybertrust Japan (CTJ)
#2007070 RESOLVED Certificate Misissuance Opened 2025-12-19 · Closed 2026-03-30 · 86% similar
SECOM: Non conformant SCT Encoding Due to SCT Modification by Cybertrust Japan (CTJ)

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action