← Cybertrust Japan / JCSI cases
Bugzilla #2007070 Self Reported Incident Certificate Misissuance Revocation Issue

SECOM: Non conformant SCT Encoding Due to SCT Modification by Cybertrust Japan (CTJ)

RESOLVED FIXED Cybertrust Japan / JCSI
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Cybertrust Japan (CTJ), an externally operated subordinate CA of SECOM, reported a compliance issue involving TLS server certificates. The problem arose when SCTs returned by CT log servers contained non-empty values in the extensions field, but the issued certificates had an empty extensions field, leading to browser validation errors. This incident was identified as a violation of TLS Baseline Requirements Section 7.1.2.11.3. A total of 180 certificates were affected, with all valid certificates revoked by December 23, 2025. CTJ has since implemented several remediation measures, including system upgrades and enhanced monitoring processes to prevent recurrence.

Model: gpt-4o-mini Generated: 2026-06-13 21:31 UTC Revised: 2026-06-16 18:43 UTC Confidence: 0.90 24 comments
Chronology
  1. CTJ updated its configuration to submit precertificates only to CT logs that return SCTs with empty extensions.
  2. All affected certificates were revoked.
Thread Activity
  1. Ml representative — Reported the incident and described the compliance failure.
  2. Ml representative — Confirmed completion of all action items related to the incident.
  3. Ml representative — Provided a closure summary detailing the incident and remediation measures.
Participants
Ml representative CCADB representative
External References
Similar Local Cases
#2021550 RESOLVED Self Reported Incident Revocation Issue Opened 2026-03-06 · Closed 2026-03-26 · 100% similar
SECOM: 2025 S/MIME CA Modified Opinion Report of Cybertrust Japan (CTJ)
#2007070 RESOLVED Certificate Misissuance Opened 2025-12-19 · Closed 2026-03-30 · 99% similar
SECOM: Non conformant SCT Encoding Due to SCT Modification by Cybertrust Japan (CTJ)
#1975624 RESOLVED Self Reported Incident Opened 2025-07-04 · Closed 2025-09-24 · 96% similar
SECOM: Cybertrust Japan's CRL lacks the critical flag in the issuingDistributionPoint extension
#1950574 RESOLVED Ca Certificate Compliance Incident Revocation Issue Opened 2025-02-26 · Closed 2025-09-15 · 95% similar
SECOM: S/MIME CA Modified Opinion Report of Cybertrust Japan (CTJ)
#2029230 RESOLVED Self Reported Incident Revocation Issue Opened 2026-04-03 · Closed 2026-05-28 · 86% similar
SSL.com: Incorrect Open MPIC Lambda implementation by EJBCA ACME Service
#2032478 ASSIGNED Self Reported Incident Certificate Misissuance Opened 2026-04-16 Still Open · 85% similar
Government of Korea: Misissuance detected by PKIMetal
#1974539 RESOLVED Self Reported Incident Revocation Issue Opened 2025-06-27 · Closed 2025-10-09 · 82% similar
DigiCert: DCV logging issue
#2004654 RESOLVED Certificate Misissuance Opened 2025-12-08 · Closed 2026-02-12 · 81% similar
SECOM: Invalid stateOrProvinceName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action