SDAIA self-reported missing S/MIME WebTrust audit coverage; trust-bit removal remains pending Microsoft deployment
SDAIA reported that it had not conducted the required WebTrust for CA - S/MIME Baseline Requirements audit for the SDAIA-operated portion of the Saudi National PKI, covering Saudi National Root CA and Government CA 2. The gap was identified during an internal compliance review, and SDAIA said S/MIME subscriber certificates had been issued under Government CA 2 during the period without the required audit coverage. SDAIA stated that issuance was stopped, Microsoft was asked to remove the S/MIME trust bit, and affected subscribers were notified. SDAIA later updated the affected population to 1,045 certificates after removing three certificates that did not contain the S/MIME EKU. SDAIA said all affected S/MIME certificates have now been revoked, and the only remaining open action is removal of the S/MIME trust capability from the affected hierarchy in coordination with Microsoft. SDAIA also said Microsoft’s August 2026 Trusted Root Program deployment notice includes the SDAIA Root CA for S/MIME distrust, with a release date of 2026-08-27 and an effective date of 2026-09-15.
- CA/B Forum S/MIME Baseline Requirements became effective for the relevant hierarchy.
- The non-compliance period for missing S/MIME audit coverage began.
- SDAIA opened a self-report about missing S/MIME WebTrust audit coverage for Saudi National Root CA and Government CA 2.
- SDAIA updated the affected certificate count from 1,048 to 1,045 after removing three certificates without S/MIME EKU.
- SDAIA said all affected S/MIME certificates had been revoked.
- SDAIA said Microsoft’s deployment notice includes the SDAIA Root CA for S/MIME distrust.
- Sdaia representative — SDAIA said no S/MIME BR audit report had been disclosed in CCADB for Saudi National Root CA and Government CA 2 since 2023-09-15 and listed remediation steps.
- Sdaia representative — SDAIA said it was finalizing the full incident report and expected to publish it by 2026-08-02 EOD.
- Sdaia representative — SDAIA posted the full incident report and said all issued S/MIME subscriber certificates were considered misissued.
- Sdaia representative — SDAIA said three previously counted certificates lacked S/MIME EKU, reduced the affected total to 1,045, and noted outstanding revocations were tracked in Bug 2058294.
- Sdaia representative — SDAIA said revocation and subscriber notification activities were continuing under the associated delayed revocation incident.
- Sdaia representative — SDAIA said action items 3, 4, and 5 were closed, while action item 2 on revocation remained in progress under Bug 2058294.
- Sdaia representative — SDAIA said all affected S/MIME certificates had now been revoked and that only the trust-bit removal action remained open.
- Sdaia representative — SDAIA said Microsoft’s August 2026 Trusted Root Program deployment notice includes the SDAIA Root CA for S/MIME distrust and that Action Item 1 will complete once the root store update is deployed.