← SECOM Trust Systems CO., LTD. cases
Bugzilla #1931515 Opened By Ca

SECOM: Issuance of TLS server certificates using keys previously compromised

RESOLVED FIXED SECOM Trust Systems CO., LTD.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

SECOM Trust Systems CO., LTD. disclosed an incident in which it was informed on 2024-11-13 by an Application Software Suppliers representative about a mis-issuance of TLS server certificates using compromised keys, in violation of Baseline Requirements section "6.1.1.3 Subscriber Key Pair Generation" (4). SECOM stated that it started the Certificate Problem Report process and investigated after receiving the report, and it revoked nine valid TLS server certificates on 2024-11-14 within 24 hours of confirming the violation. SECOM reported that its two-tiered mechanism to prevent reuse of used public keys did not work as intended because the public key check was only performed on past certificates with the same subject DN, allowing the same key to be used with a different subject DN. SECOM also implemented an infrastructure mechanism across its CAs on 2024-11-09 to prohibit issuance applications using public keys that had been compromised in the past, and it stated that this mechanism is currently prohibiting issuance of certificates with compromised keys. SECOM later reported that it planned to enhance the mechanism by 2025-01-31, and then stated that both action items were completed, including updating the mechanism to prevent reuse of previously used public keys on 2024-12-25. Mozilla indicated it intended to close the bug on or about 2-Jan-2025, and the bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:09 UTC Revised: 2026-06-16 18:53 UTC Confidence: 0.90 7 comments
Chronology
  1. SECOM was informed of a mis-issuance of TLS server certificates using compromised keys.
  2. SECOM revoked nine valid TLS server certificates identified as violating the Baseline Requirements.
  3. SECOM implemented an infrastructure mechanism across its CAs to prohibit issuance using previously compromised public keys.
  4. SECOM completed an update to its mechanism to prevent reuse of previously used public keys.
Thread Activity
  1. Ml representative — Created a preliminary incident report stating it had started the Certificate Problem Report process, revoked nine valid certificates on 2024-11-14, and identified a root cause in its public key check behavior.
  2. Ml representative — Planned to enhance the mechanism to prevent use of used public keys by 2025-01-31 and stated it would prepare an incident report by 2024-11-28.
  3. Ml representative — Posted a full incident report including impact, timeline, root cause analysis, and remediation details.
  4. Ml representative — Posted 'No updates.'
  5. Ml representative — Reported that both action items were completed, including updating the mechanism on 2024-12-25, and provided an incident closure summary.
  6. Mozilla representative — Stated an intention to close the bug on or about 2-Jan-2025 unless additional issues or questions arose.
Participants
Ml representative Mozilla representative
Similar Local Cases
#1918570 RESOLVED Root Inclusion Trust Bit Enablement Opened 2024-09-13 · Closed 2026-07-15 · 75% similar
Add SECOM SMIME RSA Root CA 2024
#1933127 RESOLVED Ca Certificate Root Program Opened By Ca Duplicate Or Superseded Opened 2024-11-25 · 74% similar
SECOM: New Subordinate CA Request(Cybertrust Japan SureServer CA G5)
#1933132 RESOLVED Ca Certificate Root Program Opened By Ca Public Discussion Opened 2024-11-25 · Closed 2025-01-31 · 74% similar
SECOM: New Subordinate CA Request(Cybertrust Japan SureMail CA G5)
#1897346 RESOLVED Certificate Misissuance Revocation Issue Opened 2024-05-17 · Closed 2024-07-24 · 63% similar
SECOM: Difference in upper and lower case between CN field and SAN
#1950574 RESOLVED Self Reported Incident Opened 2025-02-26 · Closed 2025-09-15 · 63% similar
SECOM: S/MIME CA Modified Opinion Report of Cybertrust Japan (CTJ)
#1896596 RESOLVED Certificate Misissuance Revocation Issue Opened 2024-05-14 · Closed 2024-07-24 · 61% similar
SECOM: Certificates Issued with lower case value in subject:countryName
#2004654 RESOLVED Certificate Misissuance Opened 2025-12-08 · Closed 2026-02-12 · 56% similar
SECOM: Invalid stateOrProvinceName
#1735998 RESOLVED Incident Opened 2021-10-15 · Closed 2023-02-22 · 54% similar
SECOM: Root CRLs exceed maximum validity period by 1 second

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action