SECOM: Non conformant SCT Encoding Due to SCT Modification by Cybertrust Japan (CTJ)
Cybertrust Japan (CTJ), an externally operated subordinate CA of SECOM, reported a compliance issue involving TLS server certificates. The problem arose when SCTs returned by CT log servers contained non-empty values in the extensions field, but the issued certificates had an empty extensions field, leading to browser validation errors. This incident was identified as a violation of TLS Baseline Requirements Section 7.1.2.11.3. A total of 180 certificates were affected, with all valid certificates revoked by December 23, 2025. CTJ has since implemented several remediation measures, including system upgrades and enhanced monitoring processes to prevent recurrence.
- CTJ updated its configuration to submit precertificates only to CT logs that return SCTs with empty extensions.
- All affected certificates were revoked.
- Ml representative — Reported the incident and described the compliance failure.
- Ml representative — Confirmed completion of all action items related to the incident.
- Ml representative — Provided a closure summary detailing the incident and remediation measures.