← NAVER Cloud Trust Services cases
Bugzilla #2006711 Security Incident

NAVER Cloud Trust Services: Encoding non-conformity in SCT extensions

RESOLVED FIXED NAVER Cloud Trust Services
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

NAVER Cloud Trust Services identified a technical non-conformity in the encoding of the Signed Certificate Timestamp (SCT) extension field, leading to malformed SCTs in TLS server certificates. The issue was triggered by a configuration change that caused the issuance software to improperly handle SCT data from the Static CT API. Following the discovery, the CA suspended all TLS certificate issuance on December 17, 2025, and revoked 82 affected certificates by December 22, 2025. Remediation actions included correcting the encoding logic and updating testing protocols. The incident report was finalized and all action items were completed by January 29, 2026.

Model: gpt-4o-mini Generated: 2026-06-13 20:55 UTC Revised: 2026-06-16 18:44 UTC Confidence: 0.90 11 comments
Chronology
  1. Configuration change applied to include CT log servers using the Static CT API.
  2. Incident identified and certificate issuance suspended.
  3. All affected certificates successfully revoked.
  4. All remediation action items completed.
Thread Activity
  1. Navercorp representative — Preliminary incident report submitted detailing the encoding issue.
  2. Navercorp representative — Affected certificates identified and revocation scheduled.
  3. Navercorp representative — All affected certificates successfully revoked.
  4. Navercorp representative — Weekly update provided; all action items on track.
  5. Navercorp representative — Action items update; all completed successfully.
  6. Navercorp representative — Report closure summary provided, detailing root causes and remediation.
Participants
Navercorp representative Google representative
Similar Local Cases
#1908128 RESOLVED Self Reported Incident Certificate Misissuance Opened 2024-07-16 · Closed 2024-08-28 · 63% similar
NAVER Cloud Trust Services: Certificate issued with incorrect OCSP URI in AIA
#1908130 RESOLVED Self Reported Incident Certificate Misissuance Opened 2024-07-16 · Closed 2024-08-28 · 63% similar
NAVER Cloud Trust Services: Incorrect keyUsage for ECC certificate
#1965828 RESOLVED Self Reported Incident Security Incident Opened 2025-05-12 · Closed 2025-08-19 · 61% similar
SwissSign: OCSP outage
#1446121 RESOLVED Self Reported Incident Security Incident Opened 2018-03-15 · Closed 2023-02-22 · 61% similar
IdenTrust: Improper encoding of wildcard certificate
#2012157 RESOLVED Self Reported Incident Revocation Issue Security Incident Opened 2026-01-23 · Closed 2026-03-08 · 61% similar
Actalis: Issuance of certificate using keys previously reported as compromised
#1999296 RESOLVED Security Incident Opened 2025-11-10 · Closed 2025-12-29 · 60% similar
Telia: Findings in 2025 ETSI Audit - Incident Report #1 – Vulnerability management
#1882904 RESOLVED Security Incident Opened 2024-02-29 · Closed 2025-02-12 · 60% similar
Google Trust Services: Incorrect OCSP responses for new ICAs under test
#1554259 RESOLVED Self Reported Incident Security Incident Opened 2019-05-24 · Closed 2023-02-22 · 60% similar
GlobalSign: SPKI lacks explicit NULL parameter,

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action