Microsec: CT Logging mistakes
Microsec Ltd. reported a compliance issue involving the issuance of 44 website authentication certificates with improper SCTs from CT log servers marked as 'Qualified' instead of 'Usable'. This misissuance was identified after a third-party report on December 12, 2025. The CA took immediate action by revoking the affected certificates within the required 5-day timeframe and implemented several corrective measures, including the introduction of automated monitoring for CT log lists and the use of verification tools to prevent future occurrences. The incident was resolved, and all action items have been completed, leading to the closure of the case.
- Third-party report identified CT logging mistakes.
- All affected certificates revoked.
- Incident report closure requested.
- Microsec representative — Preliminary incident report submitted.
- Microsec representative — Status report indicating no recurrence of the error.
- Microsec representative — Report closure summary provided.