← NAVER Cloud Trust Services cases
Bugzilla #2004733
Certificate Problem Report
NAVER Cloud Trust Services: CA Certificate not published in DER Encoded Format
RESOLVED
FIXED
NAVER Cloud Trust Services
AI Summary
NAVER Cloud Trust Services identified that an intermediate CA certificate's AIA extension incorrectly referenced a Root CA certificate published in PEM format instead of the required DER format, violating RFC 5280. This issue was reported by a third party and led to an internal investigation. The CA promptly replaced the non-compliant certificate and is implementing automated monitoring to prevent future occurrences. The incident was resolved on December 8, 2025, with a commitment to improve compliance processes.
Chronology
- Root CA was initially created.
- Non-compliance identified and investigation initiated.
- Non-compliant certificate replaced with DER-encoded version.
- Closure report submitted.
Participants
Hogeun Yoo
Dustin Hollenback
External References
Similar Local Cases
NAVER Cloud Trust Services: Encoding non-conformity in SCT extensions
NAVER Cloud Trust Services: Failure to respond to CPR within 24 hours
TWCA: CA Certificate not published in DER Encoded Format
OATI: AIA CA Issuer field pointing to PEM encoded cert
Chunghwa Telecom: CA Certificates Published in PEM format
Telekom Security: Root-CA certificates published in PEM encoded format
D-TRUST: EV certificates with incorrectly used businessCategory entry
SSL.com: Expired certificate for a “Valid” Test Website