← Google Trust Services LLC cases
Bugzilla #1612389 Certificate Misissuance

Google Trust Services: invalid curve-hash combination

RESOLVED FIXED Google Trust Services LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Google Trust Services LLC identified a compliance issue regarding two subordinate CAs (GTSY3 and GTSY4) that were issued with an invalid curve-hash combination, which was not permitted under the Mozilla Root Store Policy. This issue was discovered during a review following the publication of the updated Mozilla Policy 2.7. The CA took immediate action by revoking and replacing the problematic certificates. The CA has since ceased issuing certificates with this issue and has implemented procedural improvements to prevent similar occurrences in the future.

Model: gpt-4o-mini Generated: 2026-06-13 21:17 UTC Revised: 2026-06-16 18:31 UTC Confidence: 0.90 11 comments
Chronology
  1. GTSY3 and GTSY4 Subordinate CAs are issued under Mozilla Root Store Policy 2.6.1.
  2. Decision made to revoke and replace both GTSY3 and GTSY4.
  3. Bug filed to disclose the compliance issue.
Thread Activity
  1. Google representative — Reported the discovery of the invalid curve-hash combination and outlined the actions taken.
  2. Community commenter — Requested clarification on the review process that led to the compliance issue.
  3. Google representative — Confirmed that the CA has successfully revoked and re-issued the affected certificates.
  4. Fastly representative — Noted that all questions have been answered and remediation is complete.
Participants
Google representative Community commenter Fastly representative
Similar Local Cases
#1709223 RESOLVED Certificate Misissuance Opened 2021-05-03 · Closed 2023-02-22 · 88% similar
Google Trust Services: Signing SHA-1 Hash for existing CA certificate with changes in Key Usage
#1528263 RESOLVED Certificate Misissuance Opened 2019-02-15 · Closed 2023-02-22 · 80% similar
Telia: Misissued certificate - Invalid wildcard format
#1599484 RESOLVED Self Reported Incident Certificate Misissuance Opened 2019-11-26 · Closed 2023-02-22 · 80% similar
Entrust: EV Certificates Issued with Business Category "Non-Commercial" when it should have been set to "Private Organization"
#1390991 RESOLVED Ca Certificate Compliance Incident Certificate Misissuance Opened 2017-08-16 · Closed 2023-02-22 · 79% similar
Disig: Non-BR-Compliant Certificate Issuance
#1532842 RESOLVED Certificate Misissuance Opened 2019-03-06 · Closed 2023-02-22 · 78% similar
Google Trust Services: 63 bit serial numbers in some certificates
#1552586 RESOLVED Self Reported Incident Certificate Misissuance Opened 2019-05-17 · Closed 2023-02-22 · 78% similar
GlobalSign: 4 Misissued certificates with invalid CN
#1506607 RESOLVED Self Reported Incident Certificate Misissuance Opened 2018-11-12 · Closed 2026-06-10 · 77% similar
SwissSign: Misissuance of Intermediate Certificates because of incorrect organizationIdentifier
#1536213 RESOLVED Certificate Misissuance Opened 2019-03-18 · Closed 2023-02-22 · 77% similar
ACCV: Insufficient serial number entropy

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action