<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>certdesk — CA 업계 동향</title><description>CA/Browser Forum 게시물과 Mozilla CA 인컴플라이언스 사례 한국어 요약 (매일)</description><link>https://certdesk.dev/ko/news/</link><item><title>NETLOCK Certificate Problem Report [CRL RFC 5280 S5.2.3]</title><link>https://bugzilla.mozilla.org/show_bug.cgi?id=2075720</link><guid isPermaLink="true">https://bugzilla.mozilla.org/show_bug.cgi?id=2075720</guid><description>NETLOCK은 루트 CA인 NetLock Arany (Class Gold) Főtanúsítvány의 CRL이 같은 cRLNumber(39)로 두 가지 버전으로 제공되는 문제를 보고 받았다. 이 문제는 RFC 5280 §5.2.3 및 CA/Browser Forum Baseline Requirements §7.2.2에違反된다. NETLOCK은 보고를 받고 조사 중이다.</description><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><category>incident</category></item><item><title>Actalis: Incorrect Revocation dates in CRL entries</title><link>https://bugzilla.mozilla.org/show_bug.cgi?id=2075655</link><guid isPermaLink="true">https://bugzilla.mozilla.org/show_bug.cgi?id=2075655</guid><description>Actalis: Incorrect Revocation dates in CRL entries</description><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><category>incident</category></item><item><title>KIR: SZAFIR ROOT CA3 TLS CRL nextUpdate exceeds 12 months</title><link>https://bugzilla.mozilla.org/show_bug.cgi?id=2075606</link><guid isPermaLink="true">https://bugzilla.mozilla.org/show_bug.cgi?id=2075606</guid><description>KIR은 SZAFIR ROOT CA3 TLS의 CRL이 12개월을 초과하는 nextUpdate 값을 가짐을 확인했다. 이 문제는 SZAFIR ROOT CA5 SMIME의 CRL에서도 발생했다. KIR은 Baseline Requirements에 따라 새로 갱신된 CRL을 발급했다.</description><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><category>incident</category></item><item><title>Firmaprofesional: certificateHold reasonCode entries in AC Firmaprofesional - CUALIFICADOS CRL</title><link>https://bugzilla.mozilla.org/show_bug.cgi?id=2075527</link><guid isPermaLink="true">https://bugzilla.mozilla.org/show_bug.cgi?id=2075527</guid><description>Firmaprofesional은 2026년 9월 23일에 AC Firmaprofesional - CUALIFICADOS의 공용 CRL에 certificateHold reasonCode 항목이 포함되어 있다는 제3자 보고를 받았다. 이 항목들은 TLS Baseline Requirements의 4.9.13과 7.2.2 조항에 위반되는지 여부를 조사 중이다. Firmaprofesional은 해당 항목들이 포함된 CRL을 검토하고 있다.</description><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><category>incident</category></item><item><title>Telia: CRL signature algorithm property non-conformance for EC issuer key</title><link>https://bugzilla.mozilla.org/show_bug.cgi?id=2075488</link><guid isPermaLink="true">https://bugzilla.mozilla.org/show_bug.cgi?id=2075488</guid><description>Telia의 EC TLS DV CA v4에서 발급된 CRL은 서명 알고리즘 속성에서 비준수 문제가 발생했다. Telia EC TLS Root CA v3, Telia EC Email Root CA v3, Telia EC Client Root CA v3, Telia EC Signing Root CA v3에서도 같은 문제가 발견되었다. 이 문제는 잘못된 CA 설정으로 인해 발생한 것으로 확인되었다.</description><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><category>incident</category></item><item><title>NETLOCK: Certificate Problem Report [CRL URL not disclosed in CCADB]</title><link>https://bugzilla.mozilla.org/show_bug.cgi?id=2075258</link><guid isPermaLink="true">https://bugzilla.mozilla.org/show_bug.cgi?id=2075258</guid><description>NETLOCK은 CCADB에 발급 CA에 대한 CRL 배포 지점 URL을 공개하지 않은 것으로 보고되었다. 해당 문제는 제3자에 의해 보고되었으며, NETLOCK은 이 문제를 조사하고 있다. CCADB 정책 §6.2에 따르면, CA 소유자는 URL을 포함하는 첫 번째 인증서를 발급한 후 7일 이내 또는 해당 인증서를 취소한 후 4시간 이내에 이러한 URL을 CCADB에 공개해야 한다.</description><pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate><category>incident</category></item><item><title>NETLOCK: Certificate Problem Report [CRL BR S7.2.2]</title><link>https://bugzilla.mozilla.org/show_bug.cgi?id=2075255</link><guid isPermaLink="true">https://bugzilla.mozilla.org/show_bug.cgi?id=2075255</guid><description>NETLOCK의 발급 CA의 CRL에 reasonCode가 unspecified(0)으로 설정된 항목이 포함되어 있다는 보고가 제3자로부터 접수되었다. 이는 CA/Browser Forum Baseline Requirements §7.2.2에 위반된다. NETLOCK는 보고를 받고 조사 중이다.</description><pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate><category>incident</category></item><item><title>Amazon Trust Services – CP/CPS for externally operated subordinate CAs not updated in CCADB within 14 days</title><link>https://bugzilla.mozilla.org/show_bug.cgi?id=2075247</link><guid isPermaLink="true">https://bugzilla.mozilla.org/show_bug.cgi?id=2075247</guid><description>Amazon Trust Services – CP/CPS for externally operated subordinate CAs not updated in CCADB within 14 days</description><pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate><category>incident</category></item><item><title>Asseco DS / Certum: Incorrect ECDSA-SHA384 AlgorithmIdentifier Encoding in CRLs</title><link>https://bugzilla.mozilla.org/show_bug.cgi?id=2075242</link><guid isPermaLink="true">https://bugzilla.mozilla.org/show_bug.cgi?id=2075242</guid><description>Certum은 2026-09-23에 ECDSA-SHA384 AlgorithmIdentifier의 잘못된 인코딩이 포함된 15개의 CRL을 발견했다. 이 문제는 Certum이 생성한 CRL에서 발생했으며, CA/Browser Forum Baseline Requirements와 RFC 5758의 요구사항에違反한다. Certum은 영향을 받은 CRL을 확인했다.</description><pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate><category>incident</category></item><item><title>Asseco DS / Certum: CRL URLs in issued certificates not disclosed in CCADB</title><link>https://bugzilla.mozilla.org/show_bug.cgi?id=2075234</link><guid isPermaLink="true">https://bugzilla.mozilla.org/show_bug.cgi?id=2075234</guid><description>Asseco DS / Certum: CRL URLs in issued certificates not disclosed in CCADB</description><pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate><category>incident</category></item><item><title>SSL.com: Failure to Post all Root and Intermediate CA certificates in Repository identified in CP/CPS</title><link>https://bugzilla.mozilla.org/show_bug.cgi?id=2074980</link><guid isPermaLink="true">https://bugzilla.mozilla.org/show_bug.cgi?id=2074980</guid><description>SSL.com의 외부 감사관은 2025-2026년 감사 기간 중 SSL.com의 CP/CPS에서 Root CA 인증서 및 중간 CA 인증서를 저장소에 게시하지 않은 사실을 발견했다. SSL.com CP/CPS에는 Root CA 인증서와 중간 CA 인증서가 저장소에 게시되어야 한다고 규정되어 있다. SSL.com은 Baseline Requirements 및 CP/CPS에 따라 저장소에 인증서를 게시해야 한다.</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate><category>incident</category></item><item><title>Let&apos;s Encrypt: Root CRLs Missing Reason Code</title><link>https://bugzilla.mozilla.org/show_bug.cgi?id=2074944</link><guid isPermaLink="true">https://bugzilla.mozilla.org/show_bug.cgi?id=2074944</guid><description>Let&apos;s Encrypt는 ISRG Root X2, Root YR, Root YE의 Cross-Certified Subordinate CA Certificates를 취소하면서 reason code &quot;superseded&quot;를 사용했지만, 도구의 버그로 인해 reason code가 누락되었다. 이로 인해 ISRG Root X1과 ISRG Root X2의 두 개의 Root CRL에만 영향을 미쳤다. Root CRL은 수동 절차의 일부로만 발급되므로 이 사고는 제한적이다.</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate><category>incident</category></item><item><title>DigiCert:  EV JOI match with organizationIdentifer</title><link>https://bugzilla.mozilla.org/show_bug.cgi?id=2074611</link><guid isPermaLink="true">https://bugzilla.mozilla.org/show_bug.cgi?id=2074611</guid><description>DigiCert:  EV JOI match with organizationIdentifer</description><pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate><category>incident</category></item><item><title>SwissSign - Backdating of 48+h</title><link>https://bugzilla.mozilla.org/show_bug.cgi?id=2074466</link><guid isPermaLink="true">https://bugzilla.mozilla.org/show_bug.cgi?id=2074466</guid><description>스위스사인에서 발급한 TLS 인증서가 CA/Browser Forum Baseline Requirements 7.1.2.7에 따라 허용되는 최대 역연도 기간을 초과하는 것으로 확인되었다. 해당 인증서는 2026-09-20 12:35:51 UTC에 서명되었으며, notBefore 값은 2026-09-18 11:57:03 UTC였다. 이로 인해 약 48시간 38분 48초의 역연도 간격이 발생하였다.</description><pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate><category>incident</category></item><item><title>PKIoverheid: TSP KPN Delayed publication of audit attestation letters in the CCADB</title><link>https://bugzilla.mozilla.org/show_bug.cgi?id=2074032</link><guid isPermaLink="true">https://bugzilla.mozilla.org/show_bug.cgi?id=2074032</guid><description>KPN PKIoverheid은 CCADB에 subCA &quot;KPN PKIoverheid Organisatie Persoon CA - G3&quot;와 &quot;KPN PKIoverheid Organisaties Services CA - G3&quot;의 감사 증명서를 업로드하지 않았다. CCADB 정책에 따르면 92일 이내에 업로드해야 하지만, 2026-08-31에 기한이 만료되었고, 2026-09-10에 업로드되었다. 관련 정책에는 CCADB 정책 v2.1, Mozilla Root Store Policy v3.1, Microsoft Trusted Root Certificate Program이 있다.</description><pubDate>Mon, 21 Sep 2026 00:00:00 GMT</pubDate><category>incident</category></item><item><title>Ballot SC104: Set presence of AIA extension to SHOULD for Subscriber Certificates</title><link>https://cabforum.org/2026/09/03/ballot-sc104-set-presence-of-aia-extension-to-should-for-subscriber-certificates/</link><guid isPermaLink="true">https://cabforum.org/2026/09/03/ballot-sc104-set-presence-of-aia-extension-to-should-for-subscriber-certificates/</guid><description>Ballot SC104는 Subscriber Certificates의 AIA 확장의 존재를 SHOULD로 설정하는 안이다. 투표 결과, 총 21표가投じられた이다. Baseline Requirements에 따라 CA는 CRL과 OCSP를 제공해야 한다.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>ballot</category></item><item><title>Ballot SMC018: Realignment of Multipurpose use cases</title><link>https://cabforum.org/2026/08/11/ballot-smc-018/</link><guid isPermaLink="true">https://cabforum.org/2026/08/11/ballot-smc-018/</guid><description>CA/Browser Forum은 Ballot SMC018: Realignment of Multipurpose use cases를 위한 30일간의 리뷰 기간을 실시했다. 이 리뷰는 Final Maintenance Guidelines에 대한 것으로, 해당 Draft Maintenance Guideline은 여기서 확인할 수 있다. 리뷰는 CA/Browser Forum의 지적 재산권 정책(v1.4)의 4.1절에 따라 실시된다.</description><pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate><category>ballot</category></item><item><title>Ballot SC100: DNSSEC Clarification and Consolidation</title><link>https://cabforum.org/2026/08/06/ballot-sc100-dnssec-clarification-and-consolidation/</link><guid isPermaLink="true">https://cabforum.org/2026/08/06/ballot-sc100-dnssec-clarification-and-consolidation/</guid><description>Ballot SC100은 DNSSEC 관련 규정을 명확히 하고 통합했다. CA는 Baseline Requirements를 따라야 한다. Ballot SC100은 22개의 투표를 통해 결정되었다.</description><pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate><category>ballot</category></item><item><title>Ballot SC102: EV Domain Reuse and Validity Alignment</title><link>https://cabforum.org/2026/07/14/ballot-sc102-ev-domain-reuse-and-validity-alignment/</link><guid isPermaLink="true">https://cabforum.org/2026/07/14/ballot-sc102-ev-domain-reuse-and-validity-alignment/</guid><description>CA들은 Ballot SC102에 대해 투표했다. 투표 결과는 총 19표였다. Ballot SC102는 EV DomainReuse와 Validity Alignment을 다루는 Baseline Requirements이다.</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>ballot</category></item><item><title>Ballot SC0101v2: Clarify Authorization Domain Names</title><link>https://cabforum.org/2026/07/01/ballot-sc0101v2-clarify-authorization-domain-names/</link><guid isPermaLink="true">https://cabforum.org/2026/07/01/ballot-sc0101v2-clarify-authorization-domain-names/</guid><description>CA는 Baseline Requirements에 따라 Authorization Domain Names를 명시해야 한다. Ballot SC0101v2는 Authorization Domain Names를 명확히 하기 위한 투표이다. 총 27개의 투표가 있었다.</description><pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate><category>ballot</category></item><item><title>Ballot CSC-32: Make a Reserved Policy OID mandatory</title><link>https://cabforum.org/2026/06/16/ballot-csc-32-make-a-reserved-policy-oid-mandatory/</link><guid isPermaLink="true">https://cabforum.org/2026/06/16/ballot-csc-32-make-a-reserved-policy-oid-mandatory/</guid><description>Ballot CSC-32는 2025년 11월 17일에 채택되었으며, CSC BRs v3.10.0은 CABF 공개 웹사이트에 게시되었다. Ballot CSC-32는 Reserved Policy OID를 필수로 만든다. IPR 제외 공지가 제출되지 않았다.</description><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><category>ballot</category></item><item><title>Ballot SMC017v2: Increase Minimum RSA CA Key Size</title><link>https://cabforum.org/2026/06/16/ballot-smc-017v2/</link><guid isPermaLink="true">https://cabforum.org/2026/06/16/ballot-smc-017v2/</guid><description>Ballot SMC017v2는 RSA CA 키의 최소 크기를 증가시키는 내용이다. IPR 검토 기간이 완료되었고, 2026년 7월 30일부터採用되었다. 새로운 S/MIME BR v.1.0.15가 CABF 공공 웹사이트에 게시되었다.</description><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><category>ballot</category></item></channel></rss>