NAVER Cloud Trust Services: Encoding non-conformity in SCT extensions
NAVER Cloud Trust Services identified a technical non-conformity in the encoding of the Signed Certificate Timestamp (SCT) extension field, leading to malformed SCTs in TLS server certificates. The issue was triggered by a configuration change that caused the issuance software to improperly handle SCT data from the Static CT API. Following the discovery, the CA suspended all TLS certificate issuance on December 17, 2025, and revoked 82 affected certificates by December 22, 2025. Remediation actions included correcting the encoding logic and updating testing protocols. The incident report was finalized and all action items were completed by January 29, 2026.
- Configuration change applied to include CT log servers using the Static CT API.
- Incident identified and certificate issuance suspended.
- All affected certificates successfully revoked.
- All remediation action items completed.
- Navercorp representative — Preliminary incident report submitted detailing the encoding issue.
- Navercorp representative — Affected certificates identified and revocation scheduled.
- Navercorp representative — All affected certificates successfully revoked.
- Navercorp representative — Weekly update provided; all action items on track.
- Navercorp representative — Action items update; all completed successfully.
- Navercorp representative — Report closure summary provided, detailing root causes and remediation.