← Cybertrust Japan / JCSI cases
Bugzilla #2021550 Self Reported Incident Revocation Issue

SECOM: 2025 S/MIME CA Modified Opinion Report of Cybertrust Japan (CTJ)

RESOLVED FIXED Cybertrust Japan / JCSI
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

SECOM Trust Systems (SECOM) and Cybertrust Japan (CTJ) posted an audit incident report on Bugzilla due to a modified opinion in a WebTrust for S/MIME Baseline Requirements (WTSM) audit report for a subordinate CA certificate. The report concerns Cybertrust Japan SureMail CA G4, which has two subordinate CA certificates: one certificate (1) was issued before the S/MIME BR compliance date and therefore received a modified opinion, while the other certificate (2) complied and received an unqualified opinion. The CA stated that the modified opinion resulted because certificate (1) was treated as an extant S/MIME CA under Appendix B and did not receive a WebTrust Seal. As remediation, the subordinate CA certificate (1) was revoked on 2025-08-21, and SECOM and CTJ strengthened their decision-making and verification processes to prioritize best practices and enhance compliance verification. The thread also notes that no end-entity (EE) certificates were affected by the incident. The bug is resolved with resolution FIXED, and the closure report states that all disclosed action items were completed.

Model: gpt-5.4-nano Generated: 2026-06-13 21:32 UTC Revised: 2026-06-16 18:43 UTC Confidence: 0.86 6 comments
Chronology
  1. Cybertrust Japan revoked the non-compliant subordinate CA certificate (1).
  2. Cybertrust Japan received a WTSM audit and a modified opinion audit report covering the period 2024-12-11 to 2025-12-10.
  3. SECOM/CTJ posted the audit incident report on Bugzilla due to the modified opinion.
  4. SECOM/CTJ posted the report closure summary stating action items were completed.
Thread Activity
  1. Ml representative — Posted a full incident report describing the modified WTSM opinion for subordinate CA certificate (1), including timeline, impact (no EE certificates affected), and stated remediation steps.
  2. Ml representative — Provided a weekly update stating all action items were completed and that a closure report would be posted next week.
  3. Ml representative — Corrected the S/MIME BR effective/compliance date wording from the earlier bug/report text.
  4. Ml representative — Posted the report closure summary, stating the subordinate CA certificate was treated as an extant S/MIME CA, that certificate (1) was revoked on 2025-08-21, that no EE certificates were affected, and that remediation and governance commitments were completed.
  5. CCADB representative — Issued a final call for comments or questions before the bug would be closed.
Participants
Ml representative CCADB representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1950574 RESOLVED Ca Certificate Compliance Incident Revocation Issue Opened 2025-02-26 · Closed 2025-09-15 · 100% similar
SECOM: S/MIME CA Modified Opinion Report of Cybertrust Japan (CTJ)
#2007070 RESOLVED Self Reported Incident Certificate Misissuance Revocation Issue Opened 2025-12-19 · Closed 2026-03-30 · 100% similar
SECOM: Non conformant SCT Encoding Due to SCT Modification by Cybertrust Japan (CTJ)
#1975624 RESOLVED Self Reported Incident Opened 2025-07-04 · Closed 2025-09-24 · 97% similar
SECOM: Cybertrust Japan's CRL lacks the critical flag in the issuingDistributionPoint extension
#2029230 RESOLVED Self Reported Incident Revocation Issue Opened 2026-04-03 · Closed 2026-05-28 · 85% similar
SSL.com: Incorrect Open MPIC Lambda implementation by EJBCA ACME Service
#1950574 RESOLVED Self Reported Incident Opened 2025-02-26 · Closed 2025-09-15 · 84% similar
SECOM: S/MIME CA Modified Opinion Report of Cybertrust Japan (CTJ)
#1827490 RESOLVED Self Reported Incident Opened 2023-04-11 · Closed 2023-06-02 · 80% similar
Cybertrust Japan: CRL signature algorithm encoding error
#1962809 RESOLVED Self Reported Incident Revocation Issue Opened 2025-04-25 · Closed 2025-07-28 · 79% similar
SSL.com: Expired certificate for a “Valid” Test Website
#2012157 RESOLVED Self Reported Incident Revocation Issue Security Incident Opened 2026-01-23 · Closed 2026-03-08 · 79% similar
Actalis: Issuance of certificate using keys previously reported as compromised

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action