<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>certdesk — CA 業界動向</title><description>CA/Browser Forum の投稿と Mozilla CA 不適合事例の日次要約</description><link>https://certdesk.dev/ja/news/</link><item><title>NETLOCK Certificate Problem Report [CRL RFC 5280 S5.2.3]</title><link>https://bugzilla.mozilla.org/show_bug.cgi?id=2075720</link><guid isPermaLink="true">https://bugzilla.mozilla.org/show_bug.cgi?id=2075720</guid><description>NETLOCKは、ルートCAであるNetLock Arany (Class Gold) FőtanúsítványのCRLが同じcRLNumber(39)で二つのバージョンが提供されていた問題を報告を受けた。この問題はRFC 5280 §5.2.3およびCA/Browser Forum Baseline Requirements §7.2.2に違反する。NETLOCKは報告を受け調査中である。</description><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><category>incident</category></item><item><title>Actalis: Incorrect Revocation dates in CRL entries</title><link>https://bugzilla.mozilla.org/show_bug.cgi?id=2075655</link><guid isPermaLink="true">https://bugzilla.mozilla.org/show_bug.cgi?id=2075655</guid><description>Actalis: Incorrect Revocation dates in CRL entries</description><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><category>incident</category></item><item><title>KIR: SZAFIR ROOT CA3 TLS CRL nextUpdate exceeds 12 months</title><link>https://bugzilla.mozilla.org/show_bug.cgi?id=2075606</link><guid isPermaLink="true">https://bugzilla.mozilla.org/show_bug.cgi?id=2075606</guid><description>KIRはSZAFIR ROOT CA3 TLSのCRLが12ヶ月を超えるnextUpdate値を持っていることを確認した。同様の問題はSZAFIR ROOT CA5 SMIMEのCRLでも発生していた。KIRはBaseline Requirementsに従って更新されたCRLを発行した。</description><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><category>incident</category></item><item><title>Firmaprofesional: certificateHold reasonCode entries in AC Firmaprofesional - CUALIFICADOS CRL</title><link>https://bugzilla.mozilla.org/show_bug.cgi?id=2075527</link><guid isPermaLink="true">https://bugzilla.mozilla.org/show_bug.cgi?id=2075527</guid><description>Firmaprofesionalは2026年9月23日に、AC Firmaprofesional - CUALIFICADOSの公用CRLにcertificateHold reasonCodeのエントリが含まれているという第三者報告を受けた。同社は、これらのエントリがTLS Baseline Requirementsの4.9.13および7.2.2項に違反しているかどうかを調査している。</description><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><category>incident</category></item><item><title>Telia: CRL signature algorithm property non-conformance for EC issuer key</title><link>https://bugzilla.mozilla.org/show_bug.cgi?id=2075488</link><guid isPermaLink="true">https://bugzilla.mozilla.org/show_bug.cgi?id=2075488</guid><description>TeliaのEC TLS DV CA v4で発行されたCRLは、署名アルゴリズムのプロパティで非準拠問題が発生していた。Telia EC TLS Root CA v3、Telia EC Email Root CA v3、Telia EC Client Root CA v3、Telia EC Signing Root CA v3でも同様の問題が見つかった。問題は、CAの設定が間違っていたため起こったものである。</description><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><category>incident</category></item><item><title>NETLOCK: Certificate Problem Report [CRL URL not disclosed in CCADB]</title><link>https://bugzilla.mozilla.org/show_bug.cgi?id=2075258</link><guid isPermaLink="true">https://bugzilla.mozilla.org/show_bug.cgi?id=2075258</guid><description>NETLOCKは、発行CAに対するCRL配布ポイントURLをCCADBに公開していなかったと報告された。該当問題は第三者によって報告され、NETLOCKは調査を実施している。CCADBポリシー§6.2によれば、CA所有者は、URLを含む最初の証明書を発行した後7日以内、または該当証明書を撤回した後4時間以内に、これらのURLをCCADBに公開しなければならない。</description><pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate><category>incident</category></item><item><title>NETLOCK: Certificate Problem Report [CRL BR S7.2.2]</title><link>https://bugzilla.mozilla.org/show_bug.cgi?id=2075255</link><guid isPermaLink="true">https://bugzilla.mozilla.org/show_bug.cgi?id=2075255</guid><description>NETLOCKの発行CAのCRLには、reasonCodeがunspecified(0)に設定されたエントリが含まれているという第三者の報告があり、CA/Browser Forum Baseline Requirements §7.2.2に違反している。NETLOCKは報告を受けて調査中である。</description><pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate><category>incident</category></item><item><title>Amazon Trust Services – CP/CPS for externally operated subordinate CAs not updated in CCADB within 14 days</title><link>https://bugzilla.mozilla.org/show_bug.cgi?id=2075247</link><guid isPermaLink="true">https://bugzilla.mozilla.org/show_bug.cgi?id=2075247</guid><description>Amazon Trust Services – CP/CPS for externally operated subordinate CAs not updated in CCADB within 14 days</description><pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate><category>incident</category></item><item><title>Asseco DS / Certum: Incorrect ECDSA-SHA384 AlgorithmIdentifier Encoding in CRLs</title><link>https://bugzilla.mozilla.org/show_bug.cgi?id=2075242</link><guid isPermaLink="true">https://bugzilla.mozilla.org/show_bug.cgi?id=2075242</guid><description>Certumは2026-09-23に、ECDSA-SHA384 AlgorithmIdentifierのインコーディングが誤っている15個のCRLを発見した。 この問題はCertumが生成したCRLで発生しており、CA/Browser Forum Baseline RequirementsおよびRFC 5758の要件に違反している。 Certumは影響を受けたCRLを確認した。</description><pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate><category>incident</category></item><item><title>Asseco DS / Certum: CRL URLs in issued certificates not disclosed in CCADB</title><link>https://bugzilla.mozilla.org/show_bug.cgi?id=2075234</link><guid isPermaLink="true">https://bugzilla.mozilla.org/show_bug.cgi?id=2075234</guid><description>Asseco DS / Certum: CRL URLs in issued certificates not disclosed in CCADB</description><pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate><category>incident</category></item><item><title>SSL.com: Failure to Post all Root and Intermediate CA certificates in Repository identified in CP/CPS</title><link>https://bugzilla.mozilla.org/show_bug.cgi?id=2074980</link><guid isPermaLink="true">https://bugzilla.mozilla.org/show_bug.cgi?id=2074980</guid><description>SSL.comの外部監査官は、SSL.comのCP/CPSでRoot CA証明書および中間CA証明書をリポジトリに公開していないことが分かった。SSL.comのCP/CPSでは、Root CA証明書および中間CA証明書がリポジトリに公開されている必要がある。SSL.comは、Baseline RequirementsおよびCP/CPSに従って証明書をリポジトリに公開しなければならない。</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate><category>incident</category></item><item><title>Let&apos;s Encrypt: Root CRLs Missing Reason Code</title><link>https://bugzilla.mozilla.org/show_bug.cgi?id=2074944</link><guid isPermaLink="true">https://bugzilla.mozilla.org/show_bug.cgi?id=2074944</guid><description>Let&apos;s EncryptはISRG Root X2、Root YR、Root YEのCross-Certified Subordinate CA Certificatesをrevocationし、reason code &quot;superseded&quot;を使用したが、ツールのバグによりreason codeが省略された。ISRG Root X1とISRG Root X2の2つのRoot CRLのみが影響を受けた。Root CRLは手動でのceremonyの一部としてのみ発行されるため、このインシデントは限定的なものである。</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate><category>incident</category></item><item><title>DigiCert:  EV JOI match with organizationIdentifer</title><link>https://bugzilla.mozilla.org/show_bug.cgi?id=2074611</link><guid isPermaLink="true">https://bugzilla.mozilla.org/show_bug.cgi?id=2074611</guid><description>DigiCert:  EV JOI match with organizationIdentifer</description><pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate><category>incident</category></item><item><title>SwissSign - Backdating of 48+h</title><link>https://bugzilla.mozilla.org/show_bug.cgi?id=2074466</link><guid isPermaLink="true">https://bugzilla.mozilla.org/show_bug.cgi?id=2074466</guid><description>スイスサインによって発行されたTLS証明書が、CA/Browser Forum Baseline Requirements 7.1.2.7によって許可されている最大の遡及期間を超えていることが確認された。該当する証明書は、2026-09-20 12:35:51 UTCに署名され、notBefore値は2026-09-18 11:57:03 UTCであったため、約48時間38分48秒の遡及間隔が発生した。</description><pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate><category>incident</category></item><item><title>PKIoverheid: TSP KPN Delayed publication of audit attestation letters in the CCADB</title><link>https://bugzilla.mozilla.org/show_bug.cgi?id=2074032</link><guid isPermaLink="true">https://bugzilla.mozilla.org/show_bug.cgi?id=2074032</guid><description>KPN PKIoverheidは、CCADBへのsubCA &quot;KPN PKIoverheid Organisatie Persoon CA - G3&quot;と&quot;KPN PKIoverheid Organisaties Services CA - G3&quot;の監査証明書のアップロードを遅れた。CCADBポリシーの92日間の期限は2026-08-31に終了し、2026-09-10にアップロードされた。関係するポリシーには、CCADBポリシーv2.1、Mozilla Root Storeポリシーv3.1、Microsoft Trusted Root Certificateプログラムがある。</description><pubDate>Mon, 21 Sep 2026 00:00:00 GMT</pubDate><category>incident</category></item><item><title>Ballot SC104: Set presence of AIA extension to SHOULD for Subscriber Certificates</title><link>https://cabforum.org/2026/09/03/ballot-sc104-set-presence-of-aia-extension-to-should-for-subscriber-certificates/</link><guid isPermaLink="true">https://cabforum.org/2026/09/03/ballot-sc104-set-presence-of-aia-extension-to-should-for-subscriber-certificates/</guid><description>Ballot SC104は、Subscriber CertificatesのAIA拡張の存在をSHOULDに設定するものである。投票結果、合計21票が投じられた。Baseline Requirementsによれば、CAはCRLとOCSPを提供しなければならない。</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>ballot</category></item><item><title>Ballot SMC018: Realignment of Multipurpose use cases</title><link>https://cabforum.org/2026/08/11/ballot-smc-018/</link><guid isPermaLink="true">https://cabforum.org/2026/08/11/ballot-smc-018/</guid><description>CA/Browser Forumは、Ballot SMC018: Realignment of Multipurpose use casesについて、30日間のレビュー期間を実施している。このレビューは、Final Maintenance Guidelinesに関するものであり、該当するDraft Maintenance Guidelineはこちらで確認できる。このレビューは、CA/Browser Forumの知的財産権ポリシー（v1.4）の4.1節に基づいて実施されている。</description><pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate><category>ballot</category></item><item><title>Ballot SC100: DNSSEC Clarification and Consolidation</title><link>https://cabforum.org/2026/08/06/ballot-sc100-dnssec-clarification-and-consolidation/</link><guid isPermaLink="true">https://cabforum.org/2026/08/06/ballot-sc100-dnssec-clarification-and-consolidation/</guid><description>Ballot SC100はDNSSECに関する規定を明確にし、統合した。CAはBaseline Requirementsに従わなければならない。Ballot SC100は22票を得て決定された。</description><pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate><category>ballot</category></item><item><title>Ballot SC102: EV Domain Reuse and Validity Alignment</title><link>https://cabforum.org/2026/07/14/ballot-sc102-ev-domain-reuse-and-validity-alignment/</link><guid isPermaLink="true">https://cabforum.org/2026/07/14/ballot-sc102-ev-domain-reuse-and-validity-alignment/</guid><description>CAたちはBallot SC102について投票した。投票結果は合計19票だった。Ballot SC102はBaseline RequirementsにおけるEV Domain ReuseとValidity Alignmentを扱う。</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>ballot</category></item><item><title>Ballot SC0101v2: Clarify Authorization Domain Names</title><link>https://cabforum.org/2026/07/01/ballot-sc0101v2-clarify-authorization-domain-names/</link><guid isPermaLink="true">https://cabforum.org/2026/07/01/ballot-sc0101v2-clarify-authorization-domain-names/</guid><description>CAはBaseline Requirementsに従ってAuthorization Domain Namesを指定しなければならない。Ballot SC0101v2はAuthorization Domain Namesを明確にするための投票である。合計27票があった。</description><pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate><category>ballot</category></item><item><title>Ballot CSC-32: Make a Reserved Policy OID mandatory</title><link>https://cabforum.org/2026/06/16/ballot-csc-32-make-a-reserved-policy-oid-mandatory/</link><guid isPermaLink="true">https://cabforum.org/2026/06/16/ballot-csc-32-make-a-reserved-policy-oid-mandatory/</guid><description>Ballot CSC-32は2025年11月17日に採用され、CSC BRs v3.10.0はCABFの公開ウェブサイトに公開された。IPR除外通知は提出されなかった。Ballot CSC-32はReserved Policy OIDを必須とする。</description><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><category>ballot</category></item><item><title>Ballot SMC017v2: Increase Minimum RSA CA Key Size</title><link>https://cabforum.org/2026/06/16/ballot-smc-017v2/</link><guid isPermaLink="true">https://cabforum.org/2026/06/16/ballot-smc-017v2/</guid><description>Ballot SMC017v2はRSA CAキーの最小サイズを増加させる内容である。IPRレビュー期間が完了し、2026年7月30日から採用された。新しいS/MIME BR v.1.0.15がCABFのパブリックウェブサイトに公開された。</description><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><category>ballot</category></item></channel></rss>