SECOM: 2025 S/MIME CA Modified Opinion Report of Cybertrust Japan (CTJ)
SECOM Trust Systems (SECOM) and Cybertrust Japan (CTJ) posted an audit incident report on Bugzilla due to a modified opinion in a WebTrust for S/MIME Baseline Requirements (WTSM) audit report for a subordinate CA certificate. The report concerns Cybertrust Japan SureMail CA G4, which has two subordinate CA certificates: one certificate (1) was issued before the S/MIME BR compliance date and therefore received a modified opinion, while the other certificate (2) complied and received an unqualified opinion. The CA stated that the modified opinion resulted because certificate (1) was treated as an extant S/MIME CA under Appendix B and did not receive a WebTrust Seal. As remediation, the subordinate CA certificate (1) was revoked on 2025-08-21, and SECOM and CTJ strengthened their decision-making and verification processes to prioritize best practices and enhance compliance verification. The thread also notes that no end-entity (EE) certificates were affected by the incident. The bug is resolved with resolution FIXED, and the closure report states that all disclosed action items were completed.
- Cybertrust Japan revoked the non-compliant subordinate CA certificate (1).
- Cybertrust Japan received a WTSM audit and a modified opinion audit report covering the period 2024-12-11 to 2025-12-10.
- SECOM/CTJ posted the audit incident report on Bugzilla due to the modified opinion.
- SECOM/CTJ posted the report closure summary stating action items were completed.
- Ml representative — Posted a full incident report describing the modified WTSM opinion for subordinate CA certificate (1), including timeline, impact (no EE certificates affected), and stated remediation steps.
- Ml representative — Provided a weekly update stating all action items were completed and that a closure report would be posted next week.
- Ml representative — Corrected the S/MIME BR effective/compliance date wording from the earlier bug/report text.
- Ml representative — Posted the report closure summary, stating the subordinate CA certificate was treated as an extant S/MIME CA, that certificate (1) was revoked on 2025-08-21, that no EE certificates were affected, and that remediation and governance commitments were completed.
- CCADB representative — Issued a final call for comments or questions before the bug would be closed.