← Cybertrust Japan / JCSI cases
Bugzilla #1950574
Certificate Problem Report
SECOM: S/MIME CA Modified Opinion Report of Cybertrust Japan (CTJ)
RESOLVED
FIXED
Cybertrust Japan / JCSI
AI Summary
This case addresses a modified opinion in the WebTrust for S/MIME Baseline Requirements audit report for a subordinate CA certificate issued before the S/MIME BR enforcement date. The issue arose because Cybertrust Japan SureMail CA G4 had two subordinate CA certificates, one of which was not compliant with SMBR. The subordinate CA certificate was revoked on August 21, 2025, ahead of the original deadline. SECOM and CTJ have committed to monthly meetings to ensure compliance and prevent similar incidents in the future.
Chronology
- Audit incident report posted due to modified opinion in WTSM audit.
- Subordinate CA certificate revoked.
- Closure report prepared and incident report requested for closure.
Participants
SECOM Trust Systems - ONO Fumiaki
cainfo@ml.secom-sts.co.jp
chrome-root-program@google.com
bwilson@mozilla.com
incident-reporting@ccadb.org
External References
Similar Local Cases
SECOM: S/MIME CA Modified Opinion Report of Cybertrust Japan (CTJ)
Apple: Public Key Reuse
SECOM: No updated CRLs published for Cybertrust Japan SureMail CA G4
SECOM: Cybertrust Japan's CRL lacks the critical flag in the issuingDistributionPoint extension
SSL.com: Incorrect Open MPIC Lambda implementation by EJBCA ACME Service
Certigna: Multiple Reserved Certificate Policy Identifiers in CA certificates
SECOM: Difference in upper and lower case between CN field and SAN
certSIGN: delay in updating a Bugzilla ticket