← Google Trust Services LLC cases
Bugzilla #1634795
Certificate Problem Report
Google Trust Services: Incorrect revocation data temporarily served for GTS Y3 & Y4
RESOLVED
FIXED
Google Trust Services LLC
AI Summary
Google Trust Services LLC experienced an incident where incorrect revocation data was temporarily served for their GTS Y3 and Y4 certificates. This issue arose during an internal review on April 17, 2020, which revealed that batch revocation data installed on April 8 had overwritten valid revocation data. The CA took immediate action to roll back the incorrect data and restore the correct CRLs and OCSP responses by April 18, 2020. The incident was resolved, and all necessary mitigations were completed by July 2020.
Chronology
- Internal review identifies incorrect revocation data.
- Correct CRLs and OCSP responses are served.
- Final presubmit is confirmed to be working as intended.
Participants
Andy Warner
Ryan Sleevi
B Wilson
External References
Similar Local Cases
Google Trust Services: OCSP serving issue 2020-04-09
Google Trust Services: Forbidden Domain Validation Method 3.2.2.4.10
Google Trust Services: Invalid OCSP responses
Google Trust Services: Invalid ASN.1 encoding of singleExtensions in OCSP responses
Google Trust Services: CRL handling of expired certificates not fully compliant with RFC 5280 Section 3.3
Google Trust Services: Failure to revoke subscriber certificates within BR timeframe
Google Trust Services: Certificates not disclosed in CCADB
Google Trust Services: Improper OCSP response for intermediate certificate