← Google Trust Services LLC cases
Bugzilla #1581183 Repository Issue

Google Trust Services: CRL handling of expired certificates not fully compliant with RFC 5280 Section 3.3

RESOLVED FIXED Google Trust Services LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Google Trust Services reported a compliance issue in its CRL generation system for GTS CA 1O1. During an internal review and assessment on August 16, 2019, it was discovered that the CRL generation service did not include CRL entries of expired certificates because the periodic job only considered certificates with valid lifetimes, which the CA stated does not conform to RFC 5280 Section 3.3. The CA said it filed a bug to fix the issue and developed a patch that populated expired certificates in the CRL for 7 days after expiration so they appear in at least one regularly issued CRL update, and added automated testing to ensure revoked certificates are kept in the CRL. The CA reported that the patch was developed, tested, reviewed, and landed by August 19, 2019, and that remediation was completed with a staged rollout to production expected to finish by September 3, 2019 (slightly extended). In a follow-up update, the CA stated that the push to fully address the issue was completed globally shortly before 16:00 UTC on 2019-09-02 and that only two specific certificates were affected, providing crt.sh links. The bug was later marked as resolved with the CA stating remediation was complete and that no further work or information was outstanding.

Model: gpt-5.4-nano Generated: 2026-06-13 19:35 UTC Revised: 2026-06-16 18:30 UTC Confidence: 0.90 3 comments
Chronology
  1. During internal review, Google Trust Services discovered its CRL generation did not include expired-certificate entries in regularly scheduled CRLs as required by RFC 5280 Section 3.3.
  2. A patch to include expired certificates in CRLs for 7 days after expiration was developed, tested, reviewed, and landed in the codebase.
  3. Google Trust Services completed the global rollout of the remediation patch to fully address the CRL handling issue.
Thread Activity
  1. Fastly representative — Wayne Thayer posted an incident report describing the discovery, the non-compliant CRL generation behavior, and the CA’s remediation timeline and actions.
  2. Fastly representative — Wayne Thayer posted a follow-up stating the global remediation push was completed shortly before 16:00 UTC on 2019-09-02 and that only two certificates were affected, with crt.sh links.
  3. Fastly representative — Wayne Thayer stated that it appeared all questions had been answered and remediation was complete.
Participants
Fastly representative Google representative
External References
Similar Local Cases
#1729097 RESOLVED Repository Issue Opened 2021-09-03 · Closed 2023-02-22 · 78% similar
Google Trust Services: Delayed publication of CPS removing DNS Operator Exception
#1572234 RESOLVED Self Reported Incident Repository Issue Opened 2019-08-07 · Closed 2023-02-22 · 67% similar
GoDaddy: cross certificate disclosure to CCADB
#1565494 RESOLVED Audit Finding Self Reported Incident Repository Issue Opened 2019-07-12 · Closed 2024-06-30 · 67% similar
CFCA: Missed annual CPS update publication on website in 2018
#1455147 RESOLVED Ca Documents Repository Issue Opened 2018-04-18 · Closed 2023-02-22 · 67% similar
Camerfirma: Missing audit for Intermediate certificate
#1549861 RESOLVED Repository Issue Self Reported Incident Opened 2019-05-07 · Closed 2023-02-22 · 64% similar
Camerfirma: Outdated audit statements for intermediate certs
#1630040 RESOLVED Self Reported Incident Opened 2020-04-14 · Closed 2023-02-22 · 62% similar
Google Trust Services: OCSP serving issue 2020-04-09
#2009545 RESOLVED Ca Certificate Compliance Incident Repository Issue Opened 2026-01-10 · Closed 2026-02-11 · 60% similar
Microsoft PKI Services: Improper Disclosure of CRLs – Protocol Scheme
#1612389 RESOLVED Certificate Misissuance Opened 2020-01-30 · Closed 2023-02-22 · 60% similar
Google Trust Services: invalid curve-hash combination

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action