SECOM: No updated CRLs published for Cybertrust Japan SureMail CA G4
This case reports that the CRLs for Cybertrust Japan (CTJ) SureMail CA G4 were last issued and published on 2025-08-20, and that CRL publication was intentionally suspended on 2025-08-21 due to an incorrect operational procedure. As a result, no updated CRLs were published for 13 consecutive days, and the CRL expired based on its nextUpdate value on 2025-08-27 06:54 (UTC), creating non-compliance with RFC 5280. The thread also states that S/MIME Baseline Requirements require CRLs to be updated and reissued at least once every seven days, which was violated during the same period. The issue was discovered when CTJ support staff were validating a certificate in response to a general S/MIME inquiry, and CTJ published the CRL on 2025-09-03 08:59 (UTC). The bug is marked RESOLVED with resolution FIXED, and the CA provided remediation and closure updates describing completed action items including resumed CRL publication, CRL monitoring, and implementation of external monitoring, plus additional process controls and AI-based risk analysis for policy/system changes. The closure report requests closure after stating that all disclosed action items were completed as described.
- Cybertrust Japan SureMail CA G4 CRL was last issued and published.
- CRL publication was intentionally suspended due to an incorrect operational procedure.
- The last CRL expired based on its nextUpdate value.
- Non-compliance was identified and the CRL was published.
- Bug status was updated to RESOLVED (FIXED).
- Community commenter — Submitted a preliminary incident report describing that CRLs were published but not updated for 13 consecutive days, the non-compliance start based on nextUpdate, and that CTJ published the CRL after discovery.
- Community commenter — Added an attachment listing S/MIME serial SHA-256 fingerprints.
- Community commenter — Submitted a full incident report with timeline, impact counts (64 certificates), and stated contributing factors and remediation-related details.
- Community commenter — Provided a weekly status update listing action items and their completion/ongoing status, including resumption of CRL publication, monitoring, external monitoring, and process changes.
- Community commenter — Provided another weekly status update with the same action-item table, showing progress toward completion.
- Community commenter — Provided a weekly status update stating that the external monitoring action item was completed and that a closure report was being prepared.
- Community commenter — Submitted a report closure summary describing the incident root causes and remediation/commitments, and requested closure after stating all action items were completed.
- CCADB representative — Issued a final call for comments or questions on the incident report before closure.