NAVER Cloud Trust Services: AIA caIssuers URL served a PEM-encoded Root certificate instead of DER
The case concerns NAVER Cloud Trust Services’ subordinate CA certificates whose AIA extension contained a caIssuers URL pointing to a Root CA certificate file published in PEM format rather than the DER-encoded format required by RFC 5280 and the CA/Browser Forum Server Certificate Baseline Requirements. The issue was disclosed to Mozilla via a third-party report in Bugzilla (Bug ID 2004698), and NAVER acknowledged receipt and initiated an investigation. NAVER reported that the non-compliance began when the Root CA was initially created on 2017-08-18 and was identified on 2025-12-08. NAVER stated that it replaced the non-compliant PEM-encoded Root CA certificate at the referenced URL with a correctly DER-encoded certificate on 2025-12-08. NAVER also reported completing a full inventory audit of publication endpoints and adding a mandatory encoding verification step to its Root/SubCA publication SOP. The bug was marked RESOLVED with resolution FIXED, and NAVER requested closure of the incident report after stating that all disclosed action items were completed.
- The Root CA was initially created and a Root CA certificate in PEM-encoded format was published at the URL later referenced by subordinate CA AIA caIssuers fields.
- The CA identified the non-compliance via the Bugzilla third-party report and replaced the PEM-encoded Root certificate with a DER-encoded version at the referenced URL.
- NAVER submitted a report closure summary stating remediation and preventive measures were completed and requested closure.
- Navercorp representative — Submitted a preliminary incident report stating the AIA caIssuers URI referenced a PEM-encoded certificate instead of the DER-encoded format expected by RFC 5280/BR and began investigating whether other intermediates were affected.
- Navercorp representative — Submitted a full incident report describing the incident, listing affected subordinate CA certificates, stating issuance was not stopped, and providing a timeline including replacement of the PEM file with a DER-encoded certificate.
- Apple representative — Asked NAVER to confirm whether it reviews other CAs’ incident reports and how the issue was identified given it was third-party reported.
- Navercorp representative — Explained NAVER’s monitoring approach (Bugzilla/CCADB monitoring with manual verification), acknowledged omission of related incidents, and described a transition to automated Bugzilla API + AI-driven analysis and new automated controls.
- CCADB representative — Noted the report had gone stale and asked for a closure report if ready.
- Navercorp representative — Provided a report closure summary including root causes, remediation (replacement with DER, inventory audit, SOP update), and requested closure.
- CCADB representative — Issued a final call for comments and stated the report would be closed approximately 2026-01-14.