SECOM: S/MIME CA Modified Opinion Report of Cybertrust Japan (CTJ)
Cybertrust Japan (CTJ), under the SECOM root, posted an audit incident report because a subordinate CA certificate received a modified opinion in a WebTrust for S/MIME Baseline Requirements (WTSM) audit. The incident was triggered by a modified opinion for one of CTJ’s subordinate CA certificates (SureMail CA G4 certificate (1)) issued before the S/MIME BR enforcement date of 2025-02-20, while the other certificate (2) received an unqualified opinion. CTJ explained that the modified opinion occurred because certificate (1) was not SMBR-compliant, and it referenced CCADB policy guidance that a modified opinion may be treated as an incident. Mozilla asked for additional root-cause detail, including rationale for not revoking the original certificate upon issuing the corrected version and why the issue was not detected sooner. SECOM/CTJ’s action items included revoking subordinate CA certificate (1) after expiry of end-entity certificates and submitting follow-up WTSM-related reporting. The subordinate CA certificate (1) was revoked on August 21, 2025, and CTJ/SECOM stated they would complete remaining follow-up actions by receiving a WTSM audit report by February 28, 2026 and submitting an additional Audit Incident Report by March 7, 2026; Mozilla indicated the bug would be closed after a final comment period.
- WTSM audits were performed for the subordinate CA certificates, with certificate (1) receiving a modified opinion and no WebTrust Seal issued.
- SECOM/CTJ posted the incident report in Bugzilla describing the modified opinion and related timeline.
- The intermediate/subordinate CA certificate (1) was revoked.
- A closure report was posted summarizing remediation and planned follow-up actions.
- Ml representative — Posted an audit incident report explaining the modified WTSM opinion for CTJ’s subordinate CA certificate (1) issued before S/MIME BR enforcement and listed action items.
- Google representative — Requested clearer root-cause analysis, including why the original certificate was not revoked when the corrected version was issued, and asked about detection and procedural improvements.
- Ml representative — Provided rationale referencing S/MIME BR Appendix B for not revoking, described circumstances around detection, and discussed corrective actions and best-practice considerations.
- Mozilla representative — Proposed setting a next update for 1-Sept-2025 to re-evaluate closure based on completion timing of key tasks.
- Ml representative — Reported completion of the action item to revoke subordinate CA certificate (1) due to revocation of the intermediate certificate on August 21, 2025.
- Mozilla representative — Indicated the bug could be closed based on remaining items being resolved and reported separately in 2026, and left it open briefly for objections.
- Ml representative — Posted a closure report stating certificate (1) was revoked, describing added internal processes and monthly meetings, and reiterating planned follow-up audit/incident reporting dates.
- CCADB representative — Issued a final call for comments and stated the incident report would be closed approximately 2025-09-11.