← SECOM Trust Systems CO., LTD. cases
Bugzilla #2066068 Ca Certificate Compliance Incident Self Reported Incident Ccadb Disclosure Issue Remediation Tracking

SECOM cross-certificate issued without prior Chrome Root Program notification and approval

ASSIGNED SECOM Trust Systems CO., LTD.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

SECOM reported that it issued a cross-certificate from Security Communication RootCA2 to SECOM TLS RSA Root CA 2024 without first notifying the Chrome Root Program and obtaining prior express approval. SECOM said this cross-certificate extended the Chrome Root Store trust boundary to two pre-existing externally-operated JPRS subordinate CA certificates, JPRS DV RSA CA 2024 G1 and JPRS OV RSA CA 2024 G1. The bug states that SECOM had contacted the Chrome Root Program before issuance, but did not disclose that those JPRS subordinate CAs already existed beneath the subject CA or that the cross-certificate would extend trust to them. SECOM later submitted a retrospective notification form on 2026-08-27. SECOM also stated that it had not stopped subscriber certificate issuance under the affected subordinate CAs and had not identified any certificate misissuance, validation issue, private key compromise, or other technical defect affecting those subscriber certificates. The current thread indicates the retrospective notification addressed the outstanding notification and approval status, but the cross-certificate was still issued without the required prior approval at the time of issuance.

Model: gpt-5.4-mini Generated: 2026-09-06 11:00 UTC Confidence: 0.98 7 comments
Chronology
  1. SECOM issued a cross-certificate from Security Communication RootCA2 to SECOM TLS RSA Root CA 2024, extending trust to pre-existing externally-operated JPRS subordinate CAs.
  2. SECOM opened a preliminary incident report about the missing prior notification and approval.
  3. SECOM submitted a retrospective Chrome Root Program notification form for the two affected JPRS RSA subordinate CAs.
Thread Activity
  1. Ml representative — SECOM filed a preliminary incident report explaining that it had not obtained prior Chrome Root Program notification and approval before issuing the cross-certificate.
  2. Ml representative — SECOM said it had submitted the Chrome Root Program Notification of CA Certificate Issuance form retrospectively for the two affected JPRS RSA subordinate CAs.
  3. Apple representative — Apple asked SECOM to answer the impact questions using subscriber certificates under each CA certificate in scope.
  4. Ml representative — SECOM provided subscriber certificate counts, said issuance had not been stopped, and said it had not identified technical defects affecting those subscriber certificates.
  5. Ml representative — SECOM posted the full incident report and attached a CSV of CA certificates.
Participants
Ml representative Apple representative
External References
Similar Local Cases
#2058261 ASSIGNED Ca Documents Incident Self Reported Incident Policy Document Issue Opened 2026-07-27 Still Open · 69% similar
Google Trust Services: CPS Missing root program attestation
#2058920 ASSIGNED Incident Externally Reported Incident Problem Reporting Failure Remediation Tracking Opened 2026-07-29 Still Open · 69% similar
CFCA: Delayed response to CPR related with bug 2058918
#2056934 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Policy Document Issue Opened 2026-07-22 Still Open · 69% similar
Actalis: failure to timely update CP/CPS for AgID SubCAs
#2032468 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-04-16 · Closed 2026-08-09 · 69% similar
VISA: Misissuance detected by PKIMetal
#2041774 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Repository Issue Opened 2026-05-22 · Closed 2026-08-13 · 69% similar
OATI: AIA CA Issuer field pointing to PEM encoded cert
#2062162 RESOLVED Problem Reporting Failure Incident Externally Reported Incident Opened By Subscriber Or Relying Party Opened 2026-08-10 · Closed 2026-08-31 · 68% similar
HARICA: TLS server certificate issuance against CP/CPS
#2061907 RESOLVED Ca Certificate Compliance Incident Problem Reporting Failure Information Request Opened 2026-08-08 · Closed 2026-08-26 · 68% similar
Sectigo: Refusal to produce validation evidence for DV certificate issued via cPanel/WebPros subordinate CA (www.TradingExpertView.com, 2024-03-07)
#2053948 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Ccadb Disclosure Issue Opened 2026-07-09 Still Open · 68% similar
IdenTrust: Delayed disclosure of Intermediate CA in CCADB

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action