← Cybertrust Japan / JCSI cases
Bugzilla #2021550
Audit Related
SECOM: 2025 S/MIME CA Modified Opinion Report of Cybertrust Japan (CTJ)
RESOLVED
FIXED
Cybertrust Japan / JCSI
AI Summary
This incident report addresses a modified opinion in the WebTrust for S/MIME Baseline Requirements (WTSM) audit report concerning a subordinate CA certificate issued before the S/MIME BR compliance date. The affected certificate was revoked on 2025-08-21, and all End-Entity certificates were compliant with applicable requirements. The root causes included a departure from best practices, misinterpretation of requirements, and a lack of risk assessment. To prevent recurrence, Cybertrust Japan and SECOM have strengthened their verification processes and decision-making frameworks.
Chronology
- Non-compliance start date
- Non-compliance identified date
- Revocation of the non-compliant subordinate CA certificate
- Incident Report posted on Bugzilla
- Final call for comments on Incident Report
Participants
SECOM Trust Systems - ONO Fumiaki
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
SECOM: 2025 S/MIME CA Modified Opinion Report of Cybertrust Japan (CTJ)
Audit info for SECOM (Cybertrust Japan 2023-2024)
Audit info for SECOM (Cybertrust Japan 2021-2022)
SECOM: Audit info for Cybertrust Japan 2022-2023
Audit info for SECOM (Cybertrust Japan 2024-2025)
Audit info for Cybertrust Japan / JCSI
Audit info for SECOM (Cybertrust Japan 2023-2024)
Audit info for SECOM (20240607-20250606)