SECOM cross-certificate issued without prior Chrome Root Program notification and approval
SECOM reported that it issued a cross-certificate from Security Communication RootCA2 to SECOM TLS RSA Root CA 2024 without first notifying the Chrome Root Program and obtaining prior express approval. SECOM said this cross-certificate extended the Chrome Root Store trust boundary to two pre-existing externally-operated JPRS subordinate CA certificates, JPRS DV RSA CA 2024 G1 and JPRS OV RSA CA 2024 G1. The bug states that SECOM had contacted the Chrome Root Program before issuance, but did not disclose that those JPRS subordinate CAs already existed beneath the subject CA or that the cross-certificate would extend trust to them. SECOM later submitted a retrospective notification form on 2026-08-27. SECOM also stated that it had not stopped subscriber certificate issuance under the affected subordinate CAs and had not identified any certificate misissuance, validation issue, private key compromise, or other technical defect affecting those subscriber certificates. The current thread indicates the retrospective notification addressed the outstanding notification and approval status, but the cross-certificate was still issued without the required prior approval at the time of issuance.
- SECOM issued a cross-certificate from Security Communication RootCA2 to SECOM TLS RSA Root CA 2024, extending trust to pre-existing externally-operated JPRS subordinate CAs.
- SECOM opened a preliminary incident report about the missing prior notification and approval.
- SECOM submitted a retrospective Chrome Root Program notification form for the two affected JPRS RSA subordinate CAs.
- Ml representative — SECOM filed a preliminary incident report explaining that it had not obtained prior Chrome Root Program notification and approval before issuing the cross-certificate.
- Ml representative — SECOM said it had submitted the Chrome Root Program Notification of CA Certificate Issuance form retrospectively for the two affected JPRS RSA subordinate CAs.
- Apple representative — Apple asked SECOM to answer the impact questions using subscriber certificates under each CA certificate in scope.
- Ml representative — SECOM provided subscriber certificate counts, said issuance had not been stopped, and said it had not identified technical defects affecting those subscriber certificates.
- Ml representative — SECOM posted the full incident report and attached a CSV of CA certificates.