← NAVER Cloud Trust Services cases
Bugzilla #2004733 Ca Certificate Compliance

NAVER Cloud Trust Services: AIA caIssuers URL served a PEM-encoded Root certificate instead of DER

RESOLVED FIXED NAVER Cloud Trust Services
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The case concerns NAVER Cloud Trust Services’ subordinate CA certificates whose AIA extension contained a caIssuers URL pointing to a Root CA certificate file published in PEM format rather than the DER-encoded format required by RFC 5280 and the CA/Browser Forum Server Certificate Baseline Requirements. The issue was disclosed to Mozilla via a third-party report in Bugzilla (Bug ID 2004698), and NAVER acknowledged receipt and initiated an investigation. NAVER reported that the non-compliance began when the Root CA was initially created on 2017-08-18 and was identified on 2025-12-08. NAVER stated that it replaced the non-compliant PEM-encoded Root CA certificate at the referenced URL with a correctly DER-encoded certificate on 2025-12-08. NAVER also reported completing a full inventory audit of publication endpoints and adding a mandatory encoding verification step to its Root/SubCA publication SOP. The bug was marked RESOLVED with resolution FIXED, and NAVER requested closure of the incident report after stating that all disclosed action items were completed.

Model: gpt-5.4-nano Generated: 2026-06-13 20:55 UTC Revised: 2026-06-16 18:43 UTC Confidence: 0.86 7 comments
Chronology
  1. The Root CA was initially created and a Root CA certificate in PEM-encoded format was published at the URL later referenced by subordinate CA AIA caIssuers fields.
  2. The CA identified the non-compliance via the Bugzilla third-party report and replaced the PEM-encoded Root certificate with a DER-encoded version at the referenced URL.
  3. NAVER submitted a report closure summary stating remediation and preventive measures were completed and requested closure.
Thread Activity
  1. Navercorp representative — Submitted a preliminary incident report stating the AIA caIssuers URI referenced a PEM-encoded certificate instead of the DER-encoded format expected by RFC 5280/BR and began investigating whether other intermediates were affected.
  2. Navercorp representative — Submitted a full incident report describing the incident, listing affected subordinate CA certificates, stating issuance was not stopped, and providing a timeline including replacement of the PEM file with a DER-encoded certificate.
  3. Apple representative — Asked NAVER to confirm whether it reviews other CAs’ incident reports and how the issue was identified given it was third-party reported.
  4. Navercorp representative — Explained NAVER’s monitoring approach (Bugzilla/CCADB monitoring with manual verification), acknowledged omission of related incidents, and described a transition to automated Bugzilla API + AI-driven analysis and new automated controls.
  5. CCADB representative — Noted the report had gone stale and asked for a closure report if ready.
  6. Navercorp representative — Provided a report closure summary including root causes, remediation (replacement with DER, inventory audit, SOP update), and requested closure.
  7. CCADB representative — Issued a final call for comments and stated the report would be closed approximately 2026-01-14.
Participants
Navercorp representative Apple representative CCADB representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#2004668 RESOLVED Ca Certificate Compliance Opened 2025-12-08 · Closed 2026-01-20 · 78% similar
Telekom Security: Root-CA certificates published in PEM encoded format
#2047843 RESOLVED Ca Certificate Compliance Problem Reporting Failure Revocation Issue Opened 2026-06-16 · Closed 2026-07-09 · 70% similar
Certigna: Pre-certificates not recognised by the OCSP responder
#2007219 RESOLVED Ca Certificate Compliance Opened 2025-12-20 · Closed 2026-02-17 · 69% similar
DigiCert: Some certificates issued with CRLDPs that don’t exactly match CCADB disclosures
#2032485 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2026-04-16 · Closed 2026-05-04 · 69% similar
DigiCert: Misissuance detected by PKIMetal
#1988405 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2025-09-13 · Closed 2025-10-22 · 69% similar
TunTrust: Issue with Valid test Certificate
#2007105 RESOLVED Ca Certificate Compliance Opened 2025-12-19 · Closed 2026-03-30 · 68% similar
Asseco DS / Certum: CRL URLs disclosed in CCADB do not exactly match the CRL URLs in certificates
#2002281 RESOLVED Ca Certificate Compliance Opened 2025-11-25 · Closed 2025-12-11 · 66% similar
Asseco DS / Certum: Irregularities in Xinchacha/Xcc Brand SSL Certificates
#2015186 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2026-02-06 · Closed 2026-03-23 · 65% similar
DigiCert: Subject Serial Numbers for Non-Commercial Entities

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action