← Cybertrust Japan / JCSI cases
Bugzilla #2007070 Certificate Misissuance

SECOM: Non conformant SCT Encoding Due to SCT Modification by Cybertrust Japan (CTJ)

RESOLVED FIXED Cybertrust Japan / JCSI
AI Summary

A technical issue was identified with TLS server certificates issued by Cybertrust Japan (CTJ), where the Signed Certificate Timestamps (SCTs) returned by CT log servers contained values in the extensions field, but the issued certificates were encoded with an empty extensions field. This resulted in browser validation errors, violating TLS Baseline Requirements. A total of 180 certificates were affected, with 83 valid certificates revoked by December 23, 2025. Remediation measures included system reconfiguration, enhanced oversight, and the implementation of a process to verify SCT signatures.

Model: gpt-4o-mini Generated: 2026-06-13 21:31 UTC Confidence: 1.00
Chronology
  1. Non-compliance start date
  2. Non-compliance identified
  3. All affected certificates revoked
  4. Process to verify SCT signatures completed
Participants
SECOM Trust Systems - ONO Fumiaki
Similar Local Cases
#2007070 RESOLVED Certificate Misissuance Opened 2025-12-19 · Closed 2026-03-30 · 64% similar
SECOM: Non conformant SCT Encoding Due to SCT Modification by Cybertrust Japan (CTJ)
#1805866 RESOLVED Certificate Misissuance Opened 2022-12-15 · Closed 2023-02-02 · 61% similar
SECOM: One of the EV certificate was mis-issued with the incorrect Registration Number by Cybertrust Japan (CTJ)
#1805866 RESOLVED Certificate Misissuance Opened 2022-12-15 · Closed 2023-02-02 · 51% similar
SECOM: One of the EV certificate was mis-issued with the incorrect Registration Number by Cybertrust Japan (CTJ)
#1896596 RESOLVED Certificate Misissuance Opened 2024-05-14 · Closed 2024-07-24 · 47% similar
SECOM: Certificates Issued with lower case value in subject:countryName
#1969036 RESOLVED Certificate Misissuance Opened 2025-05-28 · Closed 2025-10-31 · 42% similar
Telia: TLS incorrect AIA caIssuer URI and incorrect CDP
#1848854 RESOLVED Certificate Misissuance Opened 2023-08-15 · Closed 2024-03-27 · 42% similar
SwissSign: S/MIME LCP: CN with values other than email address
#1943596 RESOLVED Certificate Misissuance Opened 2025-01-24 · Closed 2025-05-01 · 41% similar
HARICA: S/MIME certificate issuance with incorrect commonName
#1922906 RESOLVED Certificate Misissuance Opened 2024-10-05 · Closed 2025-02-12 · 41% similar
FNMT: LDAP URI in CRL Distribution Points Extension

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action