← Cybertrust Japan / JCSI cases
Bugzilla #1950574 Ca Certificate Compliance Incident Revocation Issue

SECOM: S/MIME CA Modified Opinion Report of Cybertrust Japan (CTJ)

RESOLVED FIXED Cybertrust Japan / JCSI
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Cybertrust Japan (CTJ), under the SECOM root, posted an audit incident report because a subordinate CA certificate received a modified opinion in a WebTrust for S/MIME Baseline Requirements (WTSM) audit. The incident was triggered by a modified opinion for one of CTJ’s subordinate CA certificates (SureMail CA G4 certificate (1)) issued before the S/MIME BR enforcement date of 2025-02-20, while the other certificate (2) received an unqualified opinion. CTJ explained that the modified opinion occurred because certificate (1) was not SMBR-compliant, and it referenced CCADB policy guidance that a modified opinion may be treated as an incident. Mozilla asked for additional root-cause detail, including rationale for not revoking the original certificate upon issuing the corrected version and why the issue was not detected sooner. SECOM/CTJ’s action items included revoking subordinate CA certificate (1) after expiry of end-entity certificates and submitting follow-up WTSM-related reporting. The subordinate CA certificate (1) was revoked on August 21, 2025, and CTJ/SECOM stated they would complete remaining follow-up actions by receiving a WTSM audit report by February 28, 2026 and submitting an additional Audit Incident Report by March 7, 2026; Mozilla indicated the bug would be closed after a final comment period.

Model: gpt-5.4-nano Generated: 2026-06-13 21:28 UTC Revised: 2026-06-16 18:40 UTC Confidence: 0.88 10 comments
Chronology
  1. WTSM audits were performed for the subordinate CA certificates, with certificate (1) receiving a modified opinion and no WebTrust Seal issued.
  2. SECOM/CTJ posted the incident report in Bugzilla describing the modified opinion and related timeline.
  3. The intermediate/subordinate CA certificate (1) was revoked.
  4. A closure report was posted summarizing remediation and planned follow-up actions.
Thread Activity
  1. Ml representative — Posted an audit incident report explaining the modified WTSM opinion for CTJ’s subordinate CA certificate (1) issued before S/MIME BR enforcement and listed action items.
  2. Google representative — Requested clearer root-cause analysis, including why the original certificate was not revoked when the corrected version was issued, and asked about detection and procedural improvements.
  3. Ml representative — Provided rationale referencing S/MIME BR Appendix B for not revoking, described circumstances around detection, and discussed corrective actions and best-practice considerations.
  4. Mozilla representative — Proposed setting a next update for 1-Sept-2025 to re-evaluate closure based on completion timing of key tasks.
  5. Ml representative — Reported completion of the action item to revoke subordinate CA certificate (1) due to revocation of the intermediate certificate on August 21, 2025.
  6. Mozilla representative — Indicated the bug could be closed based on remaining items being resolved and reported separately in 2026, and left it open briefly for objections.
  7. Ml representative — Posted a closure report stating certificate (1) was revoked, describing added internal processes and monthly meetings, and reiterating planned follow-up audit/incident reporting dates.
  8. CCADB representative — Issued a final call for comments and stated the incident report would be closed approximately 2025-09-11.
Participants
Ml representative Community commenter Google representative Mozilla representative CCADB representative
Similar Local Cases
#2021550 RESOLVED Self Reported Incident Revocation Issue Opened 2026-03-06 · Closed 2026-03-26 · 100% similar
SECOM: 2025 S/MIME CA Modified Opinion Report of Cybertrust Japan (CTJ)
#2007070 RESOLVED Self Reported Incident Certificate Misissuance Revocation Issue Opened 2025-12-19 · Closed 2026-03-30 · 95% similar
SECOM: Non conformant SCT Encoding Due to SCT Modification by Cybertrust Japan (CTJ)
#1769222 RESOLVED Incident Opened 2022-05-13 · Closed 2024-06-30 · 88% similar
SECOM: Failed an annual CPS update of Cybertrust Japan (CTJ)
#1924385 RESOLVED Ca Certificate Compliance Revocation Issue Closure Request Opened 2024-10-13 · Closed 2025-07-16 · 85% similar
D-Trust: Missed Revocation of TLS certificates affected by Bugzilla 1884714
#1963663 RESOLVED Incident Certificate Misissuance Opened 2025-04-30 · Closed 2025-06-12 · 85% similar
Certigna: Multiple Reserved Certificate Policy Identifiers in CA certificates
#2004732 RESOLVED Ca Certificate Compliance Incident Opened 2025-12-08 · Closed 2026-01-05 · 84% similar
Certigna: AIA CA issuer field pointing to PEM encoded cert
#2021550 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2026-03-06 · Closed 2026-03-26 · 81% similar
SECOM: 2025 S/MIME CA Modified Opinion Report of Cybertrust Japan (CTJ)
#1750631 RESOLVED Incident Revocation Issue Opened 2022-01-17 · Closed 2024-06-30 · 79% similar
SSL.com: Issuance of TLS certificates with domain validation methods prohibited by SC-45

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action