SECOM: Invalid stateOrProvinceName
SECOM Trust Systems CO., LTD. reported a compliance issue regarding TLS server certificates issued via ACME from its subordinate CAs, 'NII Open Domain CA - G7 RSA' and 'NII Open Domain CA - G7 ECC'. The certificates contained malformed `stateOrProvinceName` values, which included unexpected elements like `, C=JP`. This violation of the Baseline Requirements was identified on December 8, 2025, during a customer meeting. Following the discovery, issuance was suspended, and all affected certificates were revoked by December 10, 2025. The root causes included application defects and insufficient validation processes, which have since been addressed through various remediation actions.
- First non-compliant certificate issued.
- Issue discovered during customer meeting.
- ACME issuance suspended.
- Application fixed to prevent malformed stateOrProvinceName.
- All affected certificates revoked.
- Automatic Subject field validation completed.
- Incident report closure requested.