← Cybertrust Japan / JCSI cases
Bugzilla #1975624
Certificate Problem Report
SECOM: Cybertrust Japan's CRL lacks the critical flag in the issuingDistributionPoint extension
RESOLVED
FIXED
Cybertrust Japan / JCSI
AI Summary
On July 1, 2025, Cybertrust Japan received a notification regarding a compliance issue with the IssuingDistributionPoint extension in their CRLs, which was incorrectly marked as non-critical. This was a violation of the TLS Baseline Requirements. Following an internal investigation, Cybertrust Japan removed the extension from their CRL profiles on July 4, 2025, and implemented corrective actions including the use of a linting tool to validate CRLs before publication. A full incident report was prepared and all action items have been completed.
Chronology
- Cybertrust Japan received notification of CRL compliance issue.
- Cybertrust Japan revised CRL profiles and removed the non-critical extension.
Participants
cainfo@ml.secom-sts.co.jp
External References
Similar Local Cases
SECOM: Cybertrust Japan's CRL lacks the critical flag in the issuingDistributionPoint extension
SECOM: S/MIME CA Modified Opinion Report of Cybertrust Japan (CTJ)
Cybertrust Japan: Root CRLs exceed maximum validity period by one second
SECOM: No updated CRLs published for Cybertrust Japan SureMail CA G4
Cybertrust Japan: CRL signature algorithm encoding error
SSL.com: Incorrect Open MPIC Lambda implementation by EJBCA ACME Service
SECOM: Repository service disruption affecting subordinate CAs (CTJ)
iTrusChina: CRL Reason Codes