← Google Trust Services LLC cases
Bugzilla #1612389 Policy Compliance

Google Trust Services: invalid curve-hash combination

RESOLVED FIXED Google Trust Services LLC
AI Summary

Google Trust Services LLC identified a compliance issue regarding the use of an invalid curve-hash combination in two subordinate CAs (GTSY3 and GTSY4) created under Mozilla Policy 2.6.1. The issue arose from a misunderstanding of the policy requirements, which were clarified in the subsequent Mozilla Policy 2.7. Following the discovery, GTS ceased issuance of certificates with the problematic combination and successfully revoked and replaced the affected CAs. The organization has since implemented procedural improvements and automated compliance checks to prevent similar issues in the future.

Model: gpt-4o-mini Generated: 2026-06-13 21:17 UTC Confidence: 0.90
Chronology
  1. GTSY3 and GTSY4 Subordinate CAs issued under Mozilla Root Store Policy 2.6.1.
  2. Mozilla Root Store Policy 2.7 enters into effect.
  3. Decision made to revoke and replace both GTSY3 and GTSY4.
  4. Bug reported regarding the issue.
Participants
Andy Warner Ryan Sleevi Wayne Thayer
Similar Local Cases
#1391429 RESOLVED Policy Compliance Opened 2017-08-17 · Closed 2024-02-27 · 58% similar
GoDaddy: Non-BR-Compliant Certificate Issuance
#1575530 RESOLVED Policy Compliance Opened 2019-08-21 · Closed 2023-02-22 · 58% similar
Camerfirma: Govern d'Andorra audits
#1706976 RESOLVED Policy Compliance Opened 2021-04-22 · Closed 2022-11-14 · 57% similar
Google Trust Services: Out-of-date CPS disclosure
#1519265 RESOLVED Policy Compliance Opened 2019-01-10 · Closed 2025-08-18 · 57% similar
QuoVadis: Recap of BR Compliance in 2018 issuance by external subCAs
#1586795 RESOLVED Policy Compliance Opened 2019-10-07 · Closed 2023-02-22 · 57% similar
NetLock: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy
#1596923 RESOLVED Policy Compliance Opened 2019-11-15 · Closed 2024-06-30 · 57% similar
PKIoverheid: KPN CPS lacks CPR problem reporting instructions
#1578809 RESOLVED Policy Compliance Opened 2019-09-04 · Closed 2023-02-22 · 56% similar
PKIoverheid: Compliance issues CIBG TLS certificates
#1586125 RESOLVED Policy Compliance Opened 2019-10-03 · Closed 2024-06-30 · 56% similar
PKIoverheid: No BR Audit for Intermediate CAs technically capable of issuing TLS certs

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action