← Google Trust Services LLC cases
Bugzilla #1612389
Certificate Misissuance
Google Trust Services: invalid curve-hash combination
RESOLVED
FIXED
Google Trust Services LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
Google Trust Services LLC identified a compliance issue regarding two subordinate CAs (GTSY3 and GTSY4) that were issued with an invalid curve-hash combination, which was not permitted under the Mozilla Root Store Policy. This issue was discovered during a review following the publication of the updated Mozilla Policy 2.7. The CA took immediate action by revoking and replacing the problematic certificates. The CA has since ceased issuing certificates with this issue and has implemented procedural improvements to prevent similar occurrences in the future.
Chronology
- GTSY3 and GTSY4 Subordinate CAs are issued under Mozilla Root Store Policy 2.6.1.
- Decision made to revoke and replace both GTSY3 and GTSY4.
- Bug filed to disclose the compliance issue.
Thread Activity
- Google representative — Reported the discovery of the invalid curve-hash combination and outlined the actions taken.
- Community commenter — Requested clarification on the review process that led to the compliance issue.
- Google representative — Confirmed that the CA has successfully revoked and re-issued the affected certificates.
- Fastly representative — Noted that all questions have been answered and remediation is complete.
Participants
Google representative
Community commenter
Fastly representative
External References
Similar Local Cases
Google Trust Services: Signing SHA-1 Hash for existing CA certificate with changes in Key Usage
Telia: Misissued certificate - Invalid wildcard format
Entrust: EV Certificates Issued with Business Category "Non-Commercial" when it should have been set to "Private Organization"
Disig: Non-BR-Compliant Certificate Issuance
Google Trust Services: 63 bit serial numbers in some certificates
GlobalSign: 4 Misissued certificates with invalid CN
SwissSign: Misissuance of Intermediate Certificates because of incorrect organizationIdentifier
ACCV: Insufficient serial number entropy