← Saudi Data and Artificial Intelligence Authority (SDAIA) cases
Bugzilla #2056942 Self Reported Incident Audit Finding

SDAIA: Missing S/MIME WebTrust audit coverage

UNCONFIRMED Saudi Data and Artificial Intelligence Authority (SDAIA)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

SDAIA operates the Saudi National PKI, where the Saudi National Root CA is included in the Microsoft Trusted Root Program with the S/MIME trust bit enabled. SDAIA also operates a subordinate CA, Government CA 2, with S/MIME issuance capability. SDAIA reported that it has not conducted and disclosed the required WebTrust for CA - S/MIME Baseline Requirements audit coverage for the SDAIA-operated portion of the hierarchy (Saudi National Root CA and Government CA 2) since the S/MIME BR requirements became effective on 2023-09-15, and that no S/MIME BR audit report has been disclosed in CCADB for either CA. SDAIA states the gap was identified during an internal compliance review and that it is self-reporting the incident. SDAIA says S/MIME subscriber certificates have been issued under Government CA 2 and are currently valid, and that the exact count is being determined. SDAIA reports next steps including stopping S/MIME issuance and requesting Microsoft removal of the S/MIME trust bit (both completed), notifying affected subscribers (completed), and revoking affected certificates (in progress), with an incident report including timeline, root cause analysis, and action items to follow.

Model: gpt-5.4-nano Generated: 2026-07-22 16:30 UTC Confidence: 0.86 1 comment
Chronology
  1. SDAIA states S/MIME Baseline Requirements became effective for the relevant hierarchy.
  2. SDAIA opened a bug self-reporting missing S/MIME WebTrust audit coverage and describing remediation steps.
Thread Activity
  1. Sdaia representative — SDAIA self-reported that no S/MIME BR audit report has been disclosed in CCADB for Saudi National Root CA and Government CA 2 since 2023-09-15, and listed completed and in-progress remediation steps including stopping issuance, requesting Microsoft trust-bit removal, subscriber notification, and revocation.
Participants
Sdaia representative Mozilla representative
External References
Similar Local Cases
#2005196 RESOLVED Self Reported Incident Audit Finding Opened 2025-12-10 · Closed 2026-04-22 · 71% similar
Buypass: Findings in 2025 ETSI Audit - Audit Incident Report #2 - Supply chain policy
#1990284 RESOLVED Audit Finding Self Reported Incident Opened 2025-09-23 · Closed 2026-05-04 · 70% similar
SwissSign: recommendation on review of key pair generation implementation
#2008799 RESOLVED Self Reported Incident Audit Finding Opened 2026-01-06 · Closed 2026-02-19 · 70% similar
Chunghwa Telecom: Findings in 2025 WebTrust Audit - GTLSCA Audit Incident Report #3 - Missing vulnerability scan
#2008803 RESOLVED Self Reported Incident Audit Finding Opened 2026-01-06 · Closed 2026-02-12 · 70% similar
Chunghwa Telecom: Findings in 2025 WebTrust Audit - GTLSCA Audit Incident Report #4 - Missing evaluation for third parties
#2009045 RESOLVED Self Reported Incident Audit Finding Opened 2026-01-07 · Closed 2026-02-19 · 70% similar
Chunghwa Telecom: Delayed disclosure to Bug 2008788 GTLSCA Audit Incident Report #2 - Domain validation records without the TLS BR version
#2005194 RESOLVED Self Reported Incident Audit Finding Opened 2025-12-10 · Closed 2026-04-22 · 70% similar
Buypass: Findings in 2025 ETSI Audit - Audit Incident Report #1 - Compliance auditing on support processes
#2054448 UNCONFIRMED Self Reported Incident Certificate Misissuance Opened 2026-07-13 Still Open · 69% similar
Firmaprofesional: Chrome Root Progam Policy - Dedicated TLS hierarchy / EKU requirements
#1990277 RESOLVED Audit Finding Self Reported Incident Opened 2025-09-23 · Closed 2026-05-07 · 69% similar
SwissSign: recommendation on CA-specific risk assessment

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action