← Google Trust Services LLC cases
Bugzilla #1652581 Ca Certificate Compliance

Google Trust Services reissued root certificates to add digitalSignature KeyUsage

RESOLVED FIXED Google Trust Services LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Google Trust Services opened this bug after reviewing its root and sub-CA profiles and receiving an external note that its root CAs did not have the digitalSignature KeyUsage bit set. GTS concluded that the bit was required because the roots were used to sign OCSP responses, and it treated the missing bit as a compliance issue under section 7.1.2.1 of the Baseline Requirements. The CA said it would reissue the affected root certificates and continued serving OCSP responses from the existing roots while preparing the fix. GTS reported that the reissuance ceremony took place on 2020-08-13 without issues, and later said the revised root certificates were published on pki.goog. The thread then shifted to related questions about linting, review procedures, and a separate SHA-1 concern, but the original digitalSignature issue was described as already resolved. Mozilla later noted the issue had been resolved with the re-signing and discussed closing the bug.

Model: gpt-5.4-mini Generated: 2026-06-13 21:22 UTC Revised: 2026-06-16 18:36 UTC Confidence: 0.94 34 comments
Chronology
  1. Google Trust Services issued its root CAs and began serving OCSP responses signed using the root CA private keys.
  2. An external note alerted GTS that its root CAs did not have the digitalSignature KeyUsage bit set.
  3. GTS concluded the digitalSignature bit was required and agreed to reissue the affected root CA certificates.
  4. GTS held the reissuance ceremony and corrected the affected root certificates.
  5. GTS published the revised root certificates on pki.goog.
Thread Activity
  1. Google representative — Andy Warner filed the bug and explained that GTS had found the missing digitalSignature bit during review of related CA profile issues and an external inquiry.
  2. Community commenter — Ryan Sleevi asked what analysis supported GTS's statement that there was no immediate security or compatibility impact.
  3. Google representative — Andy Warner said GTS had tested clients and had seen no reports of problems over four years, which supported its statement.
  4. Google representative — GTS reported that the ceremony to fix the issue had taken place on 2020-08-13 and that CCADB and other updates were mostly complete.
  5. Google representative — Andy Warner explained that GTS used zlint and manual reviews, and that the review process had since been updated to require verbose lint output and explicit review of notices.
  6. Google representative — Andy Warner corrected an earlier statement about zlint history and said the review process had been changed to catch issues like this more reliably.
  7. Mozilla representative — Ben Wilson linked the related CCADB root inclusion case information.
  8. Mozilla representative — Ben Wilson stated that the digitalSignature KeyUsage issue had already been resolved by the re-signing.
Participants
Google representative Community commenter Mozilla representative Sectigo
Related Bugzilla IDs Mentioned
Similar Local Cases
#1563579 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-07-04 · Closed 2023-02-22 · 63% similar
Sectigo: Failure to provide timely incident reports
#1725039 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2021-08-10 · Closed 2023-02-22 · 63% similar
Network Solutions: 2021 Audit Observation #1
#1653504 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2020-07-17 · Closed 2023-02-22 · 62% similar
Sectigo: Certificates with RSA keys where modulus is not divisible by 8
#1815534 RESOLVED Ca Certificate Compliance Certificate Misissuance Revocation Issue Opened 2023-02-07 · Closed 2024-04-17 · 62% similar
e-commerce monitoring GmbH: SCT in precertificate
#611283 RESOLVED Ca Certificate Compliance Opened 2010-11-11 · Closed 2022-11-14 · 59% similar
StartCom cert not working in Firefox 4 beta
#1586795 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-10-07 · Closed 2023-02-22 · 58% similar
NetLock: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy
#1268225 RESOLVED Ca Certificate Compliance Opened 2016-04-27 · Closed 2022-11-14 · 58% similar
entrust: Invalid Teletext strings
#1597950 RESOLVED Ca Certificate Compliance Incident Opened 2019-11-20 · Closed 2023-02-22 · 57% similar
Sectigo: CCADB failed ALV - Ensured Root CA

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action