← Saudi Data and Artificial Intelligence Authority (SDAIA) cases
Bugzilla #2056942 Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Audit Finding

SDAIA self-reported missing S/MIME WebTrust audit coverage; trust-bit removal remains pending Microsoft deployment

ASSIGNED Saudi Data and Artificial Intelligence Authority (SDAIA)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

SDAIA reported that it had not conducted the required WebTrust for CA - S/MIME Baseline Requirements audit for the SDAIA-operated portion of the Saudi National PKI, covering Saudi National Root CA and Government CA 2. The gap was identified during an internal compliance review, and SDAIA said S/MIME subscriber certificates had been issued under Government CA 2 during the period without the required audit coverage. SDAIA stated that issuance was stopped, Microsoft was asked to remove the S/MIME trust bit, and affected subscribers were notified. SDAIA later updated the affected population to 1,045 certificates after removing three certificates that did not contain the S/MIME EKU. SDAIA said all affected S/MIME certificates have now been revoked, and the only remaining open action is removal of the S/MIME trust capability from the affected hierarchy in coordination with Microsoft. SDAIA also said Microsoft’s August 2026 Trusted Root Program deployment notice includes the SDAIA Root CA for S/MIME distrust, with a release date of 2026-08-27 and an effective date of 2026-09-15.

Model: gpt-5.4-mini Generated: 2026-07-22 16:30 UTC Revised: 2026-08-30 06:01 UTC Confidence: 0.98 9 comments
Chronology
  1. CA/B Forum S/MIME Baseline Requirements became effective for the relevant hierarchy.
  2. The non-compliance period for missing S/MIME audit coverage began.
  3. SDAIA opened a self-report about missing S/MIME WebTrust audit coverage for Saudi National Root CA and Government CA 2.
  4. SDAIA updated the affected certificate count from 1,048 to 1,045 after removing three certificates without S/MIME EKU.
  5. SDAIA said all affected S/MIME certificates had been revoked.
  6. SDAIA said Microsoft’s deployment notice includes the SDAIA Root CA for S/MIME distrust.
Thread Activity
  1. Sdaia representative — SDAIA said no S/MIME BR audit report had been disclosed in CCADB for Saudi National Root CA and Government CA 2 since 2023-09-15 and listed remediation steps.
  2. Sdaia representative — SDAIA said it was finalizing the full incident report and expected to publish it by 2026-08-02 EOD.
  3. Sdaia representative — SDAIA posted the full incident report and said all issued S/MIME subscriber certificates were considered misissued.
  4. Sdaia representative — SDAIA said three previously counted certificates lacked S/MIME EKU, reduced the affected total to 1,045, and noted outstanding revocations were tracked in Bug 2058294.
  5. Sdaia representative — SDAIA said revocation and subscriber notification activities were continuing under the associated delayed revocation incident.
  6. Sdaia representative — SDAIA said action items 3, 4, and 5 were closed, while action item 2 on revocation remained in progress under Bug 2058294.
  7. Sdaia representative — SDAIA said all affected S/MIME certificates had now been revoked and that only the trust-bit removal action remained open.
  8. Sdaia representative — SDAIA said Microsoft’s August 2026 Trusted Root Program deployment notice includes the SDAIA Root CA for S/MIME distrust and that Action Item 1 will complete once the root store update is deployed.
Participants
Sdaia representative Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#2054448 UNCONFIRMED Ca Certificate Compliance Incident Self Reported Incident Validation Issue Opened 2026-07-13 Still Open · 79% similar
Firmaprofesional: Chrome Root Progam Policy - Dedicated TLS hierarchy / EKU requirements
#2052399 RESOLVED Incident Self Reported Incident Repository Issue Remediation Tracking Opened 2026-07-03 · Closed 2026-08-08 · 75% similar
Certainly: Expired certificates on "Valid" and "Revoked" test websites
#2051459 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Security Incident Opened 2026-06-30 Still Open · 75% similar
NETLOCK: OCSP Service Returning Error for Issued Certificate
#2058294 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Revocation Issue Opened 2026-07-27 Still Open · 74% similar
SDAIA: Delayed Revocation related to Bugzilla #2056942
#2029013 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Validation Issue Opened 2026-04-02 Still Open · 72% similar
D-Trust: Missing Pre-Signing Linting for TLS Issuance
#1746945 RESOLVED Certificate Misissuance Self Reported Incident Opened 2021-12-20 · Closed 2023-02-22 · 72% similar
Amazon Trust Services: Missing CAA Check For Test Website Certificates
#1586795 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-10-07 · Closed 2023-02-22 · 71% similar
NetLock: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy
#1979475 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-07-26 · Closed 2026-07-31 · 71% similar
Microsoft PKI Services: End Entity Certificate Mis-issuance against CPS (BasicConstraints)

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action