SECOM self-reported issuance of five subordinate CA certificates without Apple prior approval
SECOM reported that it issued five subordinate CA certificates to Cybertrust Japan Co., Ltd. without obtaining Apple’s prior approval, which was required for an externally operated subordinate CA. SECOM said it discovered the non-compliance during an internal review triggered after Bugzilla 2066068 and reported the matter to the Apple Root Program the same day. Apple later told SECOM that all five subordinate CA certificates were mis-issued and that retrospective approval was not available. SECOM and Cybertrust Japan agreed that all five certificates had to be revoked, and SECOM later confirmed that revocation was completed. SECOM also updated the related CCADB records and submitted reissuance requests to the Chrome Root Program and Apple Root Program. The thread indicates that SECOM continues to investigate the full impact and will provide further updates as information becomes available.
- SECOM issued five subordinate CA certificates to Cybertrust Japan without Apple prior approval.
- SECOM identified the non-compliance during an internal review.
- SECOM reported the issue to the Apple Root Program and stopped EE issuance under the affected subordinate CAs.
- SECOM completed revocation of the five affected subordinate CA certificates.
- Ml representative — SECOM filed a preliminary incident report describing the unauthorized issuance, the affected subordinate CAs, and the planned revocation.
- Ml representative — SECOM said it had suspended issuance under the affected subordinate CAs and temporarily extended issuance under two existing subordinate CAs during the transition.
- Ml representative — SECOM reported that it had completed revocation of all five subordinate CA certificates, updated CCADB records, and submitted reissuance requests.