SECOM/CTJ self-reported CP/CPS documentation inconsistency for OCSP responder certificate profiles
SECOM Trust Systems reported a self-identified compliance issue involving Cybertrust Japan (CTJ), a subordinate CA operator in its hierarchy. The issue was that CTJ’s CP/CPS Appendix B incorrectly stated that certain OCSP responder certificate profiles included the basicConstraints extension, while CTJ’s internal profile and the issued certificates did not. SECOM said the 24 affected OCSP responder certificates were issued on 2026-08-07, and that no subscriber certificates were affected. CTJ revised the CP/CPS on 2026-08-26 and began reissuing and replacing the affected certificates, completing that work on 2026-08-28. The full incident report states the non-compliance began when the revised CP/CPS was published on 2026-08-10 and ended when the certificates were replaced on 2026-08-28. The bug remains assigned, and the thread indicates SECOM was continuing its investigation and remediation coordination with CTJ.
- CTJ issued 24 OCSP responder certificates for four subordinate CAs.
- CTJ published a revised CP/CPS that incorrectly described the OCSP responder certificate profile.
- CTJ revised the CP/CPS and began reissuing the affected OCSP responder certificates.
- The 24 affected OCSP responder certificates were replaced.
- Ml representative — SECOM opened a preliminary incident report describing the CP/CPS/profile mismatch and said it was self-reported by CTJ.
- Ml representative — SECOM said CTJ had published the revised CP/CPS and started reissuing the affected certificates.
- Ml representative — SECOM reported that reissuance and replacement of the 24 affected certificates had been completed.
- Ml representative — SECOM filed the full incident report with the timeline, impact, and remediation details.