← SECOM Trust Systems CO., LTD. cases
Bugzilla #1931515
Certificate Problem Report
SECOM: Issuance of TLS server certificates using keys previously compromised
RESOLVED
FIXED
SECOM Trust Systems CO., LTD.
AI Summary
SECOM Trust Systems faced a mis-issuance of TLS server certificates using previously compromised keys, violating Baseline Requirements. Upon notification on November 13, 2024, SECOM revoked nine valid certificates within 24 hours. The incident was attributed to a malfunction in their public key check mechanism, which allowed the same key to be reused with different subject DNs. SECOM has since updated their systems to prevent such occurrences and plans to enhance their mechanisms further by January 31, 2025.
Chronology
- Informed about mis-issuance of TLS server certificates.
- Revoked nine valid TLS server certificates.
- Planned to enhance mechanisms to prevent key reuse.
- Completed updates to prevent reuse of previously used public keys.
Participants
SECOM Trust Systems - ONO Fumiaki
External References
Similar Local Cases
SECOM: Difference in upper and lower case between CN field and SAN
SECOM: Invalid stateOrProvinceName
SECOM: S/MIME CA Modified Opinion Report of Cybertrust Japan (CTJ)
SECOM: No updated CRLs published for Cybertrust Japan SureMail CA G4
SECOM: certificate for .test TLD
SECOM: Incorrect OCSP Delegated Responder Certificate
SECOM: Outdated audit statements for intermediate certificates
SECOM: Non-BR-Compliant OCSP Responders