SECOM: Issuance of TLS server certificates using keys previously compromised
SECOM Trust Systems CO., LTD. disclosed an incident in which it was informed on 2024-11-13 by an Application Software Suppliers representative about a mis-issuance of TLS server certificates using compromised keys, in violation of Baseline Requirements section "6.1.1.3 Subscriber Key Pair Generation" (4). SECOM stated that it started the Certificate Problem Report process and investigated after receiving the report, and it revoked nine valid TLS server certificates on 2024-11-14 within 24 hours of confirming the violation. SECOM reported that its two-tiered mechanism to prevent reuse of used public keys did not work as intended because the public key check was only performed on past certificates with the same subject DN, allowing the same key to be used with a different subject DN. SECOM also implemented an infrastructure mechanism across its CAs on 2024-11-09 to prohibit issuance applications using public keys that had been compromised in the past, and it stated that this mechanism is currently prohibiting issuance of certificates with compromised keys. SECOM later reported that it planned to enhance the mechanism by 2025-01-31, and then stated that both action items were completed, including updating the mechanism to prevent reuse of previously used public keys on 2024-12-25. Mozilla indicated it intended to close the bug on or about 2-Jan-2025, and the bug is marked RESOLVED with resolution FIXED.
- SECOM was informed of a mis-issuance of TLS server certificates using compromised keys.
- SECOM revoked nine valid TLS server certificates identified as violating the Baseline Requirements.
- SECOM implemented an infrastructure mechanism across its CAs to prohibit issuance using previously compromised public keys.
- SECOM completed an update to its mechanism to prevent reuse of previously used public keys.
- Ml representative — Created a preliminary incident report stating it had started the Certificate Problem Report process, revoked nine valid certificates on 2024-11-14, and identified a root cause in its public key check behavior.
- Ml representative — Planned to enhance the mechanism to prevent use of used public keys by 2025-01-31 and stated it would prepare an incident report by 2024-11-28.
- Ml representative — Posted a full incident report including impact, timeline, root cause analysis, and remediation details.
- Ml representative — Posted 'No updates.'
- Ml representative — Reported that both action items were completed, including updating the mechanism on 2024-12-25, and provided an incident closure summary.
- Mozilla representative — Stated an intention to close the bug on or about 2-Jan-2025 unless additional issues or questions arose.