SDAIA: Missing S/MIME WebTrust audit coverage
SDAIA operates the Saudi National PKI, where the Saudi National Root CA is included in the Microsoft Trusted Root Program with the S/MIME trust bit enabled. SDAIA also operates a subordinate CA, Government CA 2, with S/MIME issuance capability. SDAIA reported that it has not conducted and disclosed the required WebTrust for CA - S/MIME Baseline Requirements audit coverage for the SDAIA-operated portion of the hierarchy (Saudi National Root CA and Government CA 2) since the S/MIME BR requirements became effective on 2023-09-15, and that no S/MIME BR audit report has been disclosed in CCADB for either CA. SDAIA states the gap was identified during an internal compliance review and that it is self-reporting the incident. SDAIA says S/MIME subscriber certificates have been issued under Government CA 2 and are currently valid, and that the exact count is being determined. SDAIA reports next steps including stopping S/MIME issuance and requesting Microsoft removal of the S/MIME trust bit (both completed), notifying affected subscribers (completed), and revoking affected certificates (in progress), with an incident report including timeline, root cause analysis, and action items to follow.
- SDAIA states S/MIME Baseline Requirements became effective for the relevant hierarchy.
- SDAIA opened a bug self-reporting missing S/MIME WebTrust audit coverage and describing remediation steps.
- Sdaia representative — SDAIA self-reported that no S/MIME BR audit report has been disclosed in CCADB for Saudi National Root CA and Government CA 2 since 2023-09-15, and listed completed and in-progress remediation steps including stopping issuance, requesting Microsoft trust-bit removal, subscriber notification, and revocation.