Open Bug 2066068 Opened 13 days ago Updated 1 day ago

SECOM: Missing Prior Notification and Approval for a Cross-Certificate Extending Trust to Externally-Operated JPRS CAs

Categories

(CA Program :: CA Certificate Compliance, task)

Tracking

(Not tracked)

ASSIGNED

People

(Reporter: cainfo, Assigned: cainfo)

Details

(Whiteboard: [ca-compliance] [ca-misissuance])

Attachments

(1 file)

No description provided.

Preliminary Incident Report

Summary

  • Incident description:

    SECOM Trust Systems Co., Ltd. ("SECOM") failed to notify the Chrome Root Program and obtain its prior express approval before issuing a cross-certificate that extended the Chrome Root Store's trust boundary to two externally-operated subordinate CA certificates operated by Japan Registry Services Co., Ltd. ("JPRS"), as required by the Chrome Root Program Policy.

    The two externally-operated subordinate CA certificates brought within the Chrome Root Store's trust boundary are:

    1. "JPRS DV RSA CA 2024 G1"
    2. "JPRS OV RSA CA 2024 G1"

    Both certificates were issued on 2024-04-04 beneath "SECOM TLS RSA Root CA 2024."

    At that time, "SECOM TLS RSA Root CA 2024" was not included in the Chrome Root Store and did not validate to a certificate included in the Chrome Root Store. SECOM therefore assessed that notification to the Chrome Root Program was not required when the two JPRS RSA subordinate CA certificates were issued.

    On 2025-04-09, SECOM issued a cross-certificate from "Security Communication RootCA2" to "SECOM TLS RSA Root CA 2024." "Security Communication RootCA2" was already included in the Chrome Root Store.

    Issuance of this cross-certificate established a trust path from a root CA certificate included in the Chrome Root Store, through "SECOM TLS RSA Root CA 2024," to the two pre-existing externally-operated JPRS RSA subordinate CAs. Consequently, issuance of the cross-certificate extended the Chrome Root Store's trust boundary to those two subordinate CAs.

    SECOM did not complete the "Chrome Root Program Notification of CA Certificate Issuance" form or obtain the express approval of the Chrome Root Program before issuing the cross-certificate.

    Before issuance of the cross-certificate, SECOM contacted the Chrome Root Program regarding its plan to issue cross-certificates, requested the latest "Chrome Root Program Notification of CA Certificate Issuance" form, and identified the issuers and subjects of the planned cross-certificates. However, SECOM did not disclose that pre-existing externally-operated JPRS RSA subordinate CAs were beneath "SECOM TLS RSA Root CA 2024" or explain that issuance of the cross-certificate would bring those subordinate CAs within the Chrome Root Store's trust boundary.

    The Chrome Root Program responded that it understood both the issuers and subjects to be owned by SECOM and that, based on that understanding, the planned cross-certificates were not considered to extend the Chrome Root Store's trust boundary, so SECOM was not required to submit the notification form.

    SECOM confirmed that the issuers and subjects were owned by SECOM and replied that it would issue the cross-certificates without submitting the notification form. SECOM did not disclose the pre-existing externally-operated JPRS RSA subordinate CAs beneath "SECOM TLS RSA Root CA 2024" or seek clarification as to whether bringing those subordinate CAs within the Chrome Root Store's trust boundary required notification and approval.

    SECOM's assessment focused on the Chrome Root Store status of the hierarchy when the JPRS RSA subordinate CA certificates were issued and did not account for the later extension of the Chrome Root Store's trust boundary through issuance of the cross-certificate.

    For comparison, SECOM had followed the Chrome Root Program notification and approval process for the following two externally-operated JPRS ECC subordinate CA certificates:

    1. "JPRS OV ECC CA 2024 G1"
    2. "JPRS DV ECC CA 2024 G1"

    These JPRS ECC subordinate CA certificates were to be issued by "Security Communication ECC RootCA1," which was already included in the Chrome Root Store.

    SECOM submitted the "Chrome Root Program Notification of CA Certificate Issuance" form on 2024-02-28. On 2024-03-08 at 20:07 UTC, the Chrome Root Program provided issuance approval for both JPRS ECC subordinate CA certificates.

    The Chrome Root Program notification and approval process was therefore understood and followed when externally-operated subordinate CA certificates were to be issued directly beneath a CA already included in the Chrome Root Store. However, this understanding was not applied to the different RSA scenario in which a subsequently issued cross-certificate extended the Chrome Root Store's trust boundary to externally-operated subordinate CA certificates that already existed beneath the cross-certified CA.

    On 2026-08-21 at 16:24 UTC, SECOM's email system received a response from the Chrome Root Program stating that issuance of the cross-certificate from "Security Communication RootCA2" to "SECOM TLS RSA Root CA 2024" had added the externally-operated JPRS subordinate CAs to the Chrome Root Store without prior authorization.

    The Chrome Root Program stated that, in its view, this violated Chrome Root Program Policy, Version 1.8, Section 1.6.1 ("Notification of CA Certificate Issuance"), and requested that SECOM complete the notification form and file a public incident report.

    On 2026-08-24, SECOM held an internal meeting from 01:00 UTC to 02:00 UTC to examine the trust path established by the cross-certificate, the status of the pre-existing JPRS RSA subordinate CAs, and the applicable Chrome Root Program Policy requirements.

    At the conclusion of that meeting at 02:00 UTC, SECOM understood and confirmed that issuance of the cross-certificate had extended the Chrome Root Store's trust boundary to the two externally-operated JPRS RSA subordinate CAs without the required prior notification and approval. SECOM treats 2026-08-24 at 02:00 UTC as the point at which it became aware of the incident.

    SECOM is submitting this Preliminary Incident Report on 2026-08-24. This submission is within 72 hours both of the Chrome Root Program's email being received by SECOM's email system and of SECOM becoming aware of the incident.

    The presently known set of CA certificates directly involved in the incident consists of:

    1. the cross-certificate issued from "Security Communication RootCA2" to "SECOM TLS RSA Root CA 2024";
    2. "JPRS DV RSA CA 2024 G1"; and
    3. "JPRS OV RSA CA 2024 G1."

    The self-signed "SECOM TLS RSA Root CA 2024" certificate is identified below as the related trust anchor represented by the cross-certificate.

    The investigation into the complete scope, contributing factors, and impact of the incident remains ongoing. The cross-certificate and the two JPRS RSA subordinate CA certificates remain valid.

    SECOM is continuing to investigate:

    • why the pre-issuance review for the cross-certificate did not identify that the cross-certificate would extend the Chrome Root Store's trust boundary to the pre-existing JPRS RSA subordinate CAs;
    • whether any other CA certificates or PKI hierarchies are affected by the same failure;
    • which procedural, technical, and review controls require modification to prevent recurrence; and
    • the complete scope and impact of the incident.

    SECOM will provide a detailed timeline, final scope and impact assessment, root cause analysis, lessons learned, and corresponding remediation actions in its Full Incident Report.

    SECOM intends to complete the "Chrome Root Program Notification of CA Certificate Issuance" form for the affected JPRS RSA subordinate CA certificates as a retrospective notification.

  • Relevant policies:

    Chrome Root Program Policy, Version 1.6, Section 7.1 ("Notification of CA Certificate Issuance"), which was in effect when the cross-certificate was issued on 2025-04-09.

    Version 1.6, Section 7.1 required CA Owners included in the Chrome Root Store to complete the "Chrome Root Program Notification of CA Certificate Issuance" form at least three weeks before a CA in the corresponding hierarchy issued a CA certificate that:

    • extended the Chrome Root Store's trust boundary; or
    • replaced an unrevoked and unexpired CA certificate whose subject certificate CA Owner was not explicitly included in the Chrome Root Store.

    Version 1.6, Section 7.1 identified cross-certificates issued to CA Owners not represented in the Chrome Root Store and externally-operated CA certificates as examples of applicable use cases. It also stated that such CA certificates must not be issued without the express approval of the Chrome Root Program.

    The Chrome Root Program identified this matter as non-compliance with Chrome Root Program Policy, Version 1.8, Section 1.6.1 ("Notification of CA Certificate Issuance"), which was the current version when the Chrome Root Program notified SECOM of the incident in August 2026.

    The requirement in Version 1.8, Section 1.6.1 corresponds to the requirement contained in Version 1.6, Section 7.1 when the cross-certificate was issued.

  • Source of incident disclosure:

    Third Party Reported. The non-compliance was identified by the Chrome Root Program during its review of CCADB Case 00002753.

Preliminary Impact Information

  • Total number of certificates: 3 CA certificates are presently known to be directly involved in this incident.

  • Total number of "remaining valid" certificates: 3. All three CA certificates presently known to be directly involved remain valid.

  • Affected certificate types: One cross-certificate and two externally-operated subordinate CA certificates associated with DV and OV certificate issuance.

  • Incident heuristic: The complete presently known set consists of:

    1. the cross-certificate with SHA-256 fingerprint C8FB5BB81193CA9B531E2A0A568F14CC75D20924B98D2724DD243F63D813CF13;
    2. "JPRS DV RSA CA 2024 G1"; and
    3. "JPRS OV RSA CA 2024 G1."

    SECOM is continuing to investigate whether any other CA certificates or PKI hierarchies are affected by the same condition.

  • Was issuance stopped in response to this incident, and why or why not?: Yes. As an interim measure, SECOM stopped the issuance of any additional cross-certificate or externally-operated subordinate CA certificate that could extend the Chrome Root Store's trust boundary until the applicable Chrome Root Program notification and approval requirements have been evaluated.

  • Additional considerations: The self-signed "SECOM TLS RSA Root CA 2024" certificate is the related trust anchor represented by the cross-certificate. It is listed below to describe the relevant trust path but is not included in the count of three CA certificates directly involved in the incident.

SECOM TLS RSA Root CA 2024, self-signed certificate

  • Issuer: C=JP, O=SECOM Trust Systems Co., Ltd., CN=SECOM TLS RSA Root CA 2024
  • Subject: C=JP, O=SECOM Trust Systems Co., Ltd., CN=SECOM TLS RSA Root CA 2024
  • Validity period: January 31, 2024 05:11:55 GMT to January 14, 2049 05:11:55 GMT
  • SHA-256 fingerprint: 1435F225C5D252D7A21948CC3CE62AECFA88001E3DD72D1CC3555100EB372F93

Cross-certificate for SECOM TLS RSA Root CA 2024

  • Issuer: C=JP, O=SECOM Trust Systems Co., Ltd., OU=Security Communication RootCA2
  • Subject: C=JP, O=SECOM Trust Systems Co., Ltd., CN=SECOM TLS RSA Root CA 2024
  • Validity period: April 9, 2025 05:28:15 GMT to May 29, 2029 05:00:39 GMT
  • SHA-256 fingerprint: C8FB5BB81193CA9B531E2A0A568F14CC75D20924B98D2724DD243F63D813CF13

JPRS DV RSA CA 2024 G1

  • Issuer: C=JP, O=SECOM Trust Systems Co., Ltd., CN=SECOM TLS RSA Root CA 2024
  • Subject: C=JP, O=Japan Registry Services Co., Ltd., CN=JPRS DV RSA CA 2024 G1
  • Validity period: April 4, 2024 04:50:03 GMT to January 12, 2039 00:00:00 GMT
  • SHA-256 fingerprint: 52361A6ABC835E7AD4B375F2165055303169DDE9FBEB4FAAF588ED532DDC2DCB

JPRS OV RSA CA 2024 G1

  • Issuer: C=JP, O=SECOM Trust Systems Co., Ltd., CN=SECOM TLS RSA Root CA 2024
  • Subject: C=JP, O=Japan Registry Services Co., Ltd., CN=JPRS OV RSA CA 2024 G1
  • Validity period: April 4, 2024 05:05:41 GMT to January 12, 2039 00:00:00 GMT
  • SHA-256 fingerprint: DAFA254E0173F0FD793A92ECFDF2C72C53EA5A761A73B7A3394C49182EA90933

If the scope changes, SECOM will clearly disclose:

  • the corrected scope;
  • when the change was identified;
  • the circumstances that caused the earlier scope to be incomplete; and
  • the measures taken to avoid similar inaccuracies.

Preliminary Timeline

All dates and times below are stated in UTC.

Date and time Event
2024-01-31T05:11Z The self-signed "SECOM TLS RSA Root CA 2024" certificate was issued.
2024-02-28 SECOM submitted the "Chrome Root Program Notification of CA Certificate Issuance" form for "JPRS DV ECC CA 2024 G1" and "JPRS OV ECC CA 2024 G1," which were to be issued by "Security Communication ECC RootCA1."
2024-03-08T20:07Z The Chrome Root Program provided issuance approval for "JPRS DV ECC CA 2024 G1" and "JPRS OV ECC CA 2024 G1."
2024-04-04T04:50Z "JPRS DV RSA CA 2024 G1" was issued beneath "SECOM TLS RSA Root CA 2024." At this time, "SECOM TLS RSA Root CA 2024" was not included in the Chrome Root Store and did not validate to a certificate included in the Chrome Root Store.
2024-04-04T05:05Z "JPRS OV RSA CA 2024 G1" was issued beneath "SECOM TLS RSA Root CA 2024." At this time, "SECOM TLS RSA Root CA 2024" was not included in the Chrome Root Store and did not validate to a certificate included in the Chrome Root Store.
2024-04-04T05:30Z "JPRS DV ECC CA 2024 G1" was issued beneath "Security Communication ECC RootCA1." At this time, "Security Communication ECC RootCA1" was included in the Chrome Root Store.
2024-04-04T05:53Z "JPRS OV ECC CA 2024 G1" was issued beneath "Security Communication ECC RootCA1." At this time, "Security Communication ECC RootCA1" was included in the Chrome Root Store.
2024-12-01T19:50Z SECOM contacted the Chrome Root Program regarding its plan to issue cross-certificates, requested the latest "Chrome Root Program Notification of CA Certificate Issuance" form, and identified the issuers and subjects of the planned cross-certificates. SECOM did not disclose that the pre-existing externally-operated JPRS RSA subordinate CAs were beneath "SECOM TLS RSA Root CA 2024."
2024-12-02T16:33Z The Chrome Root Program responded that it understood both the issuers and subjects to be owned by SECOM and that, based on that understanding, the planned cross-certificates were not considered to extend the Chrome Root Store's trust boundary, so SECOM was not required to submit the notification form.
2024-12-03T02:34Z SECOM confirmed that the issuers and subjects were owned by SECOM and replied that it would issue the cross-certificates without submitting the notification form. SECOM did not disclose the pre-existing externally-operated JPRS RSA subordinate CAs beneath "SECOM TLS RSA Root CA 2024" or seek clarification as to whether bringing them within the Chrome Root Store's trust boundary required notification and approval.
2025-04-09T05:28Z SECOM issued a cross-certificate from "Security Communication RootCA2" to "SECOM TLS RSA Root CA 2024." This established a trust path from the Chrome Root Store to the two pre-existing externally-operated JPRS RSA subordinate CAs. SECOM did not submit the required prior notification or obtain the express approval of the Chrome Root Program before issuing the cross-certificate.
2026-08-21T16:24Z SECOM's email system received a response from the Chrome Root Program stating that issuance of the cross-certificate had added the externally-operated JPRS subordinate CAs to the Chrome Root Store without prior authorization and, in the Chrome Root Program's view, violated Chrome Root Program Policy, Version 1.8, Section 1.6.1. The Chrome Root Program requested that SECOM complete the notification form and file a public incident report.
2026-08-24T01:00Z/2026-08-24T02:00Z SECOM held an internal meeting to examine the relevant trust path, the status of the pre-existing JPRS RSA subordinate CAs, and the applicable requirements of Chrome Root Program Policy, Version 1.6, Section 7.1 and Version 1.8, Section 1.6.1.
2026-08-24T02:00Z At the conclusion of the internal meeting, SECOM understood and confirmed that issuance of the cross-certificate had extended the Chrome Root Store's trust boundary to the two externally-operated JPRS RSA subordinate CAs without the required prior notification and approval. SECOM treats this as the point at which it became aware of the incident.
Assignee: nobody → cainfo
Status: UNCONFIRMED → ASSIGNED
Type: defect → task
Ever confirmed: true
Whiteboard: [ca-compliance] [ca-misissuance]

Status Update – 2026-08-27

On 2026-08-27 at 11:10 UTC, SECOM submitted the "Chrome Root Program Notification of CA Certificate Issuance" form to the Chrome Root Program as a retrospective notification for the two affected externally-operated JPRS RSA subordinate CA certificates, "JPRS DV RSA CA 2024 G1" and "JPRS OV RSA CA 2024 G1."

In response to Comment 1:

These three responses appear to consider impact only for CA Certificates:

  • Total number of certificates:
  • Total number of "remaining valid" certificates:
  • Was issuance stopped in response to this incident, and why or why not?:

Can you answer each one with the lens of Subscriber Certificates under each of the CA Certificates in scope of this bug?

(In reply to Dustin Hollenback (Apple) from comment #3)

Thank you for the clarification.

The following information is stated as of 2026-08-27.
The figures include server certificates issued through both ACME and non-ACME services.

Total number of Subscriber Certificates

The issuance counts are separated into the period before, and the period on or after, the issuance of the cross-certificate from "Security Communication RootCA2" to "SECOM TLS RSA Root CA 2024" on 2025-04-09.

JPRS DV RSA CA 2024 G1

  • Server certificates issued from 2024-04-04 through 2025-04-08: 26
  • Server certificates issued from 2025-04-09 through 2026-08-27: 53,261

JPRS OV RSA CA 2024 G1

  • Server certificates issued from 2024-04-04 through 2025-04-08: 2
  • Server certificates issued from 2025-04-09 through 2026-08-27: 701

Total number of remaining valid Subscriber Certificates

As of 2026-08-27:

  • Valid server certificates issued under "JPRS DV RSA CA 2024 G1": 52,892
  • Valid server certificates issued under "JPRS OV RSA CA 2024 G1": 691

Was issuance stopped in response to this incident, and why or why not?

No. Issuance of Subscriber Certificates under "JPRS DV RSA CA 2024 G1" and "JPRS OV RSA CA 2024 G1" was not stopped in response to this incident.

SECOM's current assessment is that the identified non-compliance concerns the Chrome Root Program's prior notification and approval requirements associated with the issuance of the cross-certificate from "Security Communication RootCA2" to "SECOM TLS RSA Root CA 2024."

In assessing whether Subscriber Certificate issuance should be suspended, SECOM also considered that valid JPRS subordinate CA certificates already existed directly under "Security Communication RootCA2," and that the Chrome Root Program had previously approved the issuance of JPRS subordinate CA certificates under "Security Communication ECC RootCA1."

SECOM did not treat these circumstances as constituting notification or approval for "JPRS DV RSA CA 2024 G1" or "JPRS OV RSA CA 2024 G1." Rather, SECOM considered them as part of its interim assessment of whether continued Subscriber Certificate issuance under the two affected subordinate CAs presented any additional technical or security risk.

SECOM has not identified any certificate misissuance, validation issue, certificate profile issue, private key compromise, or other technical defect affecting Subscriber Certificates issued under the two affected JPRS subordinate CAs.

Based on the presently known facts, SECOM determined that suspension of Subscriber Certificate issuance was not necessary. SECOM therefore did not suspend issuance under the two affected subordinate CAs or revoke the currently valid Subscriber Certificates solely in response to this notification and approval incident.

SECOM is continuing to investigate the complete scope and impact of the incident. If the investigation identifies any additional impact on Subscriber Certificates or any condition requiring further action, SECOM will promptly disclose the findings and corresponding actions through this incident report.

Full Incident Report

Summary

  • CA Owner CCADB unique ID: SECOM Trust Systems: A000045

  • Incident description:

    SECOM Trust Systems Co., Ltd. ("SECOM") failed to notify the Chrome Root Program and obtain its prior express approval before issuing a cross-certificate from "Security Communication RootCA2" to "SECOM TLS RSA Root CA 2024."

    The issuance of this cross-certificate extended the Chrome Root Store's trust boundary to the following two pre-existing externally-operated subordinate CA certificates operated by Japan Registry Services Co., Ltd. ("JPRS"):

    • "JPRS DV RSA CA 2024 G1"
    • "JPRS OV RSA CA 2024 G1"

    Both JPRS RSA subordinate CA certificates were issued beneath "SECOM TLS RSA Root CA 2024" on 2024-04-04.

    At the time those two subordinate CA certificates were issued, "SECOM TLS RSA Root CA 2024" was not included in the Chrome Root Store and did not validate to a certificate included in the Chrome Root Store. SECOM therefore assessed that notification to the Chrome Root Program was not required at that time.

    On 2025-04-09, SECOM issued a cross-certificate from "Security Communication RootCA2," which was already included in the Chrome Root Store, to "SECOM TLS RSA Root CA 2024."

    The cross-certificate established a trust path from the Chrome Root Store, through "SECOM TLS RSA Root CA 2024," to the two pre-existing externally-operated JPRS RSA subordinate CAs.

    Before issuing the cross-certificate, SECOM contacted the Chrome Root Program regarding its plan to issue cross-certificates, requested the latest "Chrome Root Program Notification of CA Certificate Issuance" form, and identified the issuers and subjects of the planned cross-certificates.

    However, SECOM did not disclose that the pre-existing externally-operated JPRS RSA subordinate CAs were beneath "SECOM TLS RSA Root CA 2024" or explain that issuance of the cross-certificate would bring those subordinate CAs within the Chrome Root Store's trust boundary.

    The Chrome Root Program responded that it understood both the issuers and subjects of the planned cross-certificates to be owned by SECOM and that, based on that understanding, the planned cross-certificates were not considered to extend the Chrome Root Store's trust boundary.

    SECOM confirmed that the issuers and subjects were owned by SECOM and proceeded with issuance without submitting the notification form. SECOM did not correct the Chrome Root Program's incomplete understanding by disclosing the externally-operated subordinate CAs beneath the subject CA or seek clarification regarding whether the resulting extension of trust required notification and approval.

  • Timeline summary:

    • Non-compliance start date: 2025-04-09T05:28:15Z

    • Non-compliance identified date: 2026-08-24T02:00:00Z

    • Non-compliance end date: Date of approval of the retrospective notification.

      SECOM submitted the retrospective notification at 2026-08-27T11:10:00Z.

      This retrospective acceptance addressed the outstanding notification and approval status but does not change the fact that the cross-certificate was issued without the notification and prior express approval required at the time of issuance.

  • Relevant policies:

    Chrome Root Program Policy, Version 1.6, Section 7.1 ("Notification of CA Certificate Issuance"), which was in effect when the cross-certificate was issued on 2025-04-09.

    Version 1.6, Section 7.1 required CA Owners included in the Chrome Root Store to complete the "Chrome Root Program Notification of CA Certificate Issuance" form at least three weeks before a CA in the corresponding hierarchy issued a CA certificate that:

    • extended the Chrome Root Store's trust boundary; or
    • replaced an unrevoked and unexpired CA certificate whose subject certificate CA Owner was not explicitly included in the Chrome Root Store.

    Version 1.6, Section 7.1 identified cross-certificates issued to CA Owners not represented in the Chrome Root Store and externally-operated CA certificates as examples of applicable use cases. It also stated that such CA certificates must not be issued without the express approval of the Chrome Root Program.

    The Chrome Root Program identified this matter as non-compliance with Chrome Root Program Policy, Version 1.8, Section 1.6.1 ("Notification of CA Certificate Issuance"), which was the current version when the Chrome Root Program notified SECOM of the incident in August 2026.

    The requirement in Version 1.8, Section 1.6.1 corresponds to the requirement contained in Version 1.6, Section 7.1 when the cross-certificate was issued.

  • Source of incident disclosure: Third Party Reported.

    The non-compliance was identified by the Chrome Root Program during its review of CCADB Case 00002753.

Impact

  • Total number of certificates:

    The incident directly involved the following three CA certificates:

    1. The cross-certificate issued from "Security Communication RootCA2" to "SECOM TLS RSA Root CA 2024"
    2. "JPRS DV RSA CA 2024 G1"
    3. "JPRS OV RSA CA 2024 G1"

    In addition, as of 2026-08-27, a total of 53,990 Subscriber Certificates had been issued under the two affected JPRS RSA subordinate CAs. This figure includes certificates issued through both ACME and non-ACME services.

    The breakdown is as follows:

    • "JPRS DV RSA CA 2024 G1"

      • Issued from 2024-04-04 through 2025-04-08: 26
      • Issued from 2025-04-09 through 2026-08-27: 53,261
      • Total: 53,287
    • "JPRS OV RSA CA 2024 G1"

      • Issued from 2024-04-04 through 2025-04-08: 2
      • Issued from 2025-04-09 through 2026-08-27: 701
      • Total: 703

    Combined totals:

    • Issued before 2025-04-09: 28
    • Issued from 2025-04-09 through 2026-08-27: 53,962
    • Total issued through 2026-08-27: 53,990
  • Total number of "remaining valid" certificates:

    The three directly involved CA certificates remained valid as of 2026-08-27.

    As of 2026-08-27, 53,583 Subscriber Certificates issued under the affected subordinate CAs remained valid:

    • Valid server certificates under "JPRS DV RSA CA 2024 G1": 52,892
    • Valid server certificates under "JPRS OV RSA CA 2024 G1": 691
    • Total remaining valid server certificates: 53,583
  • Affected certificate types:

    • This incident directly involves:

      • one cross-certificate; and
      • two externally-operated subordinate CA certificates associated with DV and OV TLS server certificate issuance.

      SECOM did not identify any non-compliance or technical defect affecting the DV or OV Subscriber Certificates issued under the two subordinate CAs.

  • Incident heuristic:

    The directly involved CA certificate corpus consists of:

    1. The cross-certificate with SHA-256 fingerprint:
      C8FB5BB81193CA9B531E2A0A568F14CC75D20924B98D2724DD243F63D813CF13

    2. "JPRS DV RSA CA 2024 G1," with SHA-256 fingerprint:
      52361A6ABC835E7AD4B375F2165055303169DDE9FBEB4FAAF588ED532DDC2DCB

    3. "JPRS OV RSA CA 2024 G1," with SHA-256 fingerprint:
      DAFA254E0173F0FD793A92ECFDF2C72C53EA5A761A73B7A3394C49182EA90933

    The Subscriber Certificate corpus consists of all Subscriber Certificates issued under:

    • "JPRS DV RSA CA 2024 G1"; and
    • "JPRS OV RSA CA 2024 G1"

    from the issuance of each subordinate CA certificate through 2026-08-27.

    The 53,962 Subscriber Certificates issued from 2025-04-09 through 2026-08-27 were issued after the Chrome Root Store trust path was established through the cross-certificate.

    Subscriber Certificates issued under the two JPRS RSA subordinate CAs are not included in this corpus because SECOM did not identify any non-compliance, misissuance, validation issue, certificate profile issue, private key compromise, or other technical defect affecting those Subscriber Certificates.

  • Was issuance stopped in response to this incident, and why or why not?:

    No. SECOM did not stop Subscriber Certificate issuance under "JPRS DV RSA CA 2024 G1" or "JPRS OV RSA CA 2024 G1" in response to this incident.

    SECOM's assessment was that the identified non-compliance concerned the Chrome Root Program's prior notification and approval requirements associated with issuance of the cross-certificate.

    SECOM did not identify certificate misissuance, a certificate profile issue, a validation issue, private key compromise, unauthorized use of a CA private key, compromise of CA systems, or another technical defect affecting Subscriber Certificates issued under the two affected subordinate CAs.

    In assessing whether Subscriber Certificate issuance should be suspended, SECOM also considered that:

    • valid JPRS subordinate CA certificates already existed directly beneath "Security Communication RootCA2"; and
    • the Chrome Root Program had previously approved issuance of JPRS subordinate CA certificates beneath "Security Communication ECC RootCA1."

    SECOM did not treat those circumstances as notification or approval for "JPRS DV RSA CA 2024 G1" or "JPRS OV RSA CA 2024 G1." They were considered only as part of the interim assessment of whether continued Subscriber Certificate issuance presented an additional technical or security risk.

    Based on the facts known at that time, SECOM determined that suspension of Subscriber Certificate issuance and revocation of the valid Subscriber Certificates solely because of this notification and approval incident were not necessary.

    Following further review, SECOM recognized that it should have independently and more explicitly documented its operational risk assessment after receiving notification of the non-compliance, including the reasons for continuing issuance, the risks associated with suspension, the risks associated with continued issuance, and the alternatives considered.

  • Analysis:

    • N/A. Whiteboard does not contain revocation-delay.
  • Additional considerations:

    The self-signed "SECOM TLS RSA Root CA 2024" certificate is the related trust anchor represented by the cross-certificate. It is included below to describe the relevant trust path but is not included in the count of the three CA certificates directly involved in the incident.

    SECOM submitted the "Chrome Root Program Notification of CA Certificate Issuance" form at 2026-08-27T11:10:00Z as a retrospective notification for:

    • "JPRS DV RSA CA 2024 G1"
    • "JPRS OV RSA CA 2024 G1"

    The Chrome Root Program also encouraged SECOM to evaluate transitioning from the externally-operated subordinate CA model to a model in which SECOM directly owns and operates issuing CAs on behalf of its partners.

Timeline

All dates and times below are stated in UTC.

Date and time Event
2024-01-31T05:11:55Z The self-signed "SECOM TLS RSA Root CA 2024" certificate was issued.
2024-02-28 SECOM submitted the "Chrome Root Program Notification of CA Certificate Issuance" form for "JPRS DV ECC CA 2024 G1" and "JPRS OV ECC CA 2024 G1," which were to be issued beneath "Security Communication ECC RootCA1." The exact submission time is not available.
2024-03-08T20:07:00Z The Chrome Root Program approved issuance of "JPRS DV ECC CA 2024 G1" and "JPRS OV ECC CA 2024 G1."
2024-04-04T04:50:03Z "JPRS DV RSA CA 2024 G1" was issued beneath "SECOM TLS RSA Root CA 2024." "SECOM TLS RSA Root CA 2024" was not included in the Chrome Root Store and did not validate to a certificate included in the Chrome Root Store.
2024-04-04T05:05:41Z "JPRS OV RSA CA 2024 G1" was issued beneath "SECOM TLS RSA Root CA 2024." "SECOM TLS RSA Root CA 2024" was not included in the Chrome Root Store and did not validate to a certificate included in the Chrome Root Store.
2024-04-04T05:30:00Z "JPRS DV ECC CA 2024 G1" was issued beneath "Security Communication ECC RootCA1."
2024-04-04T05:53:00Z "JPRS OV ECC CA 2024 G1" was issued beneath "Security Communication ECC RootCA1."
2024-12-01T19:50:00Z SECOM contacted the Chrome Root Program regarding its plan to issue cross-certificates, requested the latest notification form, and identified the issuers and subjects of the planned cross-certificates. SECOM did not disclose the pre-existing externally-operated JPRS RSA subordinate CAs beneath "SECOM TLS RSA Root CA 2024."
2024-12-02T16:33:00Z The Chrome Root Program responded that it understood both the issuers and subjects to be owned by SECOM and, based on that understanding, considered that the planned cross-certificates would not extend the Chrome Root Store's trust boundary.
2024-12-03T02:34:00Z SECOM confirmed that the issuers and subjects were owned by SECOM and stated that it would issue the cross-certificates without submitting the notification form. SECOM did not disclose the externally-operated JPRS RSA subordinate CAs beneath the subject CA or seek clarification regarding the resulting extension of trust.
2025-04-09T05:28:15Z SECOM issued the cross-certificate from "Security Communication RootCA2" to "SECOM TLS RSA Root CA 2024." This established a trust path from the Chrome Root Store to the two pre-existing externally-operated JPRS RSA subordinate CAs. The non-compliance began.
2026-08-17T14:15:00Z During its review of CCADB Case 00002753, the Chrome Root Program sent SECOM additional questions and requests for clarification.
2026-08-18 SECOM submitted a correction request through CCADB Case 00003409 regarding cross-certificate disclosures on Root records. The exact submission time is not available.
2026-08-19T11:31:00Z SECOM informed the Chrome Root Program that it had submitted the correction request and was reviewing the remaining questions.
2026-08-20T06:22:00Z SECOM explained its previous understanding regarding the JPRS externally-operated subordinate CA notifications and proposed submitting a retrospective notification.
2026-08-21T16:24:00Z SECOM's email system received the Chrome Root Program's response stating that issuance of the cross-certificate had added unauthorized externally-operated JPRS subordinate CAs to the Chrome Root Store and, in Chrome's view, violated Chrome Root Program Policy, Version 1.8, Section 1.6.1. Chrome requested completion of the notification form and filing of a public incident report.
2026-08-24T01:00:00Z to 2026-08-24T02:00:00Z SECOM held an internal meeting to examine the trust path, the status of the pre-existing JPRS RSA subordinate CAs, and the applicable Chrome Root Program Policy requirements.
2026-08-24T02:00:00Z SECOM confirmed that the cross-certificate had extended the Chrome Root Store's trust boundary to the two externally-operated JPRS RSA subordinate CAs without the required prior notification and approval. SECOM treats this as the time it became aware of the incident.
2026-08-24T11:10:00Z SECOM informed its Qualified Auditor of this incident.
2026-08-27T11:10:00Z SECOM submitted the notification form as a retrospective notification for the two affected JPRS RSA subordinate CA certificates.
2026-08-28T09:00:00Z SECOM revised its technical review checklist to add mandatory Root Program approval checks for externally-operated subordinate CAs.

Related Incidents

Bug Date Description
Bug 2068053 2026-09-01 This incident also concerns the issuance of externally-operated subordinate CA certificates without obtaining the prior approval required by a Root Store Operator. Bug 2068053 concerns five subordinate CA certificates issued for Cybertrust Japan without Apple prior approval. Both incidents identified gaps in SECOM's process for determining and verifying applicable Root Program notification and approval requirements before CA certificate issuance.

Root Cause Analysis

Contributing Factor #1: The review evaluated only the direct issuer-to-subject relationship of the cross-certificate and did not assess the resulting changes to the complete PKI hierarchy and trust paths.

  • Description:

    SECOM's review primarily evaluated the issuer, subject, certificate profile, cryptographic properties, and direct issuer-to-subject relationship of the planned cross-certificate.

    The review did not require SECOM to identify all existing subordinate CAs beneath the subject CA or determine whether issuance of the cross-certificate would cause any of those subordinate CAs to enter the Chrome Root Store's trust boundary.

  • Timeline:

    This factor existed when the cross-certificate was reviewed between 2024-12-01 and 2025-04-09. It directly affected the issuance decision at 2025-04-09T05:28:15Z.

  • Detection:

    The issue was identified by the Chrome Root Program during its review of CCADB Case 00002753 and was communicated to SECOM at 2026-08-21T16:24:00Z.

  • Interaction with other factors:

    N/A. This report identifies a single contributing factor. The incomplete communication to the Chrome Root Program and the absence of a mandatory approval gate were consequences of the incomplete assessment of the PKI hierarchy and resulting trust paths.

  • Root Cause Analysis methodology used:

    5 Whys and a process-control review of the CA certificate issuance workflow.

Lessons Learned

  • What went well:

    • SECOM responded to the Chrome Root Program's questions and performed an internal review.
    • SECOM filed the Preliminary Incident Report within 72 hours of receiving the Chrome Root Program's notification and confirming the incident.
    • SECOM submitted retrospective notifications for the two affected JPRS RSA subordinate CA certificates.
    • SECOM obtained and publicly disclosed the Subscriber Certificate issuance and validity counts.
    • SECOM identified no Subscriber Certificate misissuance, validation issue, certificate profile issue, private key compromise, or other technical defect.
    • SECOM revised its technical review checklist to include Root Program approval checks for externally-operated subordinate CAs.
  • What didn’t go well:

    • SECOM evaluated the proposed cross-certificate without assessing the resulting changes to the complete PKI hierarchy and trust paths.
    • SECOM did not provide complete hierarchy information to the Chrome Root Program.
    • SECOM did not correct the Chrome Root Program's incomplete understanding before issuance.
    • SECOM's workflow did not prevent signing without documented evidence of applicable Root Program notification and approval.
    • The correct process used for the JPRS ECC subordinate CAs was not generalized to the RSA cross-certificate scenario.
  • Where we got lucky:

    • No technical defect, private key compromise, certificate profile issue, validation issue, or Subscriber Certificate misissuance was identified under the affected subordinate CAs.
    • The Chrome Root Program identified the issue during its review of CCADB Case 00002753. SECOM's internal controls did not independently detect the issue.
    • The externally-operated subordinate CAs and the resulting trust paths could be identified using retained certificate and hierarchy records.
  • Additional:

    • A CA certificate must be reviewed as a change to the complete trust graph and not only as an individual certificate.
    • Root Program notification and approval requirements apply to the resulting trust effect of issuance, including the effect on pre-existing descendant CAs.
    • Communications with Root Store Operators must identify all information material to the applicability decision, including descendant CAs and their operators.
    • Incident impact assessments must consider both CA certificates and all Subscriber Certificates within the affected trust paths.

Action Items

Action Item Kind Corresponding Root Cause(s) Evaluation Criteria Due Date Status
#1 Submit retrospective Chrome notifications for the two affected JPRS RSA subordinate CA certificates. Mitigate Contributing Factor #1 Notifications for both certificates were submitted and recorded. 2026-08-27 Complete
#2 Publicly disclose the Subscriber Certificate counts under the two JPRS RSA subordinate CAs and the rationale for continued issuance. Mitigate Contributing Factor #1 The counts and rationale were published in Bugzilla 2066068. 2026-08-28 Complete
#3 Add applicable Root Program notification and approval checks to the technical review checklist for externally-operated subordinate CAs. Prevent Contributing Factor #1 The revised checklist includes the required Root Program checks. 2026-08-28 Complete
#4 Require documented trust-path analysis and an independently verified Root Program compliance gate before issuing applicable CA certificates. Prevent Contributing Factor #1 The revised checklist for trust-path analysis includes the required Root Program checks. 2026-08-28 Complete
#5 Conduct mandatory training and a tabletop exercise for relevant personnel. Prevent / Detect Contributing Factor #1 All relevant personnel complete the training and demonstrate correct application of the revised controls. 2026-09-11 Ongoing
#6 Evaluate alternatives to the externally-operated subordinate CA model, inform the Qualified Auditor, and review the effectiveness of the corrective actions. Mitigate / Detect Contributing Factor #1 The model assessment, auditor communication, and corrective-action effectiveness review are completed and documented. 2026-09-18 Ongoing

Appendix

A. CA Certificate Details

The Appendix identifies the three CA certificates directly involved in this incident and the related self-signed "SECOM TLS RSA Root CA 2024" certificate used to describe the relevant trust path.

Please refer to the attached file.

SECOM TLS RSA Root CA 2024, Self-Signed Certificate
  • Issuer: C=JP, O=SECOM Trust Systems Co., Ltd., CN=SECOM TLS RSA Root CA 2024
  • Subject: C=JP, O=SECOM Trust Systems Co., Ltd., CN=SECOM TLS RSA Root CA 2024
  • Not Before: 2024-01-31T05:11:55Z
  • Not After: 2049-01-14T05:11:55Z
  • SHA-256 fingerprint: 1435F225C5D252D7A21948CC3CE62AECFA88001E3DD72D1CC3555100EB372F93
Cross-Certificate for SECOM TLS RSA Root CA 2024
  • Issuer: C=JP, O=SECOM Trust Systems Co., Ltd., OU=Security Communication RootCA2
  • Subject: C=JP, O=SECOM Trust Systems Co., Ltd., CN=SECOM TLS RSA Root CA 2024
  • Not Before: 2025-04-09T05:28:15Z
  • Not After: 2029-05-29T05:00:39Z
  • SHA-256 fingerprint: C8FB5BB81193CA9B531E2A0A568F14CC75D20924B98D2724DD243F63D813CF13
JPRS DV RSA CA 2024 G1
  • Issuer: C=JP, O=SECOM Trust Systems Co., Ltd., CN=SECOM TLS RSA Root CA 2024
  • Subject: C=JP, O=Japan Registry Services Co., Ltd., CN=JPRS DV RSA CA 2024 G1
  • Not Before: 2024-04-04T04:50:03Z
  • Not After: 2039-01-12T00:00:00Z
  • SHA-256 fingerprint: 52361A6ABC835E7AD4B375F2165055303169DDE9FBEB4FAAF588ED532DDC2DCB
JPRS OV RSA CA 2024 G1
  • Issuer: C=JP, O=SECOM Trust Systems Co., Ltd., CN=SECOM TLS RSA Root CA 2024
  • Subject: C=JP, O=Japan Registry Services Co., Ltd., CN=JPRS OV RSA CA 2024 G1
  • Not Before: 2024-04-04T05:05:41Z
  • Not After: 2039-01-12T00:00:00Z
  • SHA-256 fingerprint: DAFA254E0173F0FD793A92ECFDF2C72C53EA5A761A73B7A3394C49182EA90933
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: