Google Trust Services disclosed a CPS documentation error involving TLS-ALPN validation method references
This case concerns Google Trust Services (GTS) disclosing that its CPS still referenced Baseline Requirements domain validation method 3.2.2.4.10 after that method had been retired and replaced by TLS-ALPN. The issue was first raised by Andrew Ayer, who pointed out that the CPS text described a forbidden validation method. GTS acknowledged the report, prepared an incident report, updated its CPS to remove the outdated reference and add the current method, and said it reviewed its configurations and confirmed TLS-ALPN was the only random-number-based validation method it had used since 2020-09-22. GTS also stated that revocation was needed, re-issuance began and completed on 2021-05-01, and revocation of the associated certificates completed the same day. The thread later notes that GTS implemented tooling to mirror relevant Mozilla Bugzilla incidents into its internal tracking system. The bug was ultimately resolved FIXED, and Mozilla staff indicated it seemed ready to be closed.
- Baseline Requirements version 1.7.3 took effect and removed method 10, replacing it with method 20 for TLS-ALPN.
- Mozilla Bug 1706967 was filed about GTS CPS text referencing the retired validation method.
- GTS updated its CPS to remove method 10 and add method 20.
- Associated certificates were re-issued and revoked.
- GTS said it had deployed tooling to mirror Mozilla Bugzilla incidents into its internal tracking system.
- Mm representative — Andrew Ayer reported that GTS's CPS still described forbidden BR method 3.2.2.4.10.
- Google representative — GTS acknowledged the report and said an incident report was being prepared.
- Community commenter — GTS attached an incident report describing the timeline, affected certificates, and remediation steps.
- Community commenter — Ryan Sleevi questioned the adequacy and accuracy of the incident report and raised concerns about GTS's compliance processes.
- Google representative — GTS said it was preparing a new report to address the concerns.
- Google representative — GTS submitted a revised incident report with an updated timeline and certificate details.
- Community commenter — Ryan Sleevi said the revised report still did not sufficiently identify the root causes.
- Google representative — GTS said it had implemented tooling to mirror Mozilla Bugzilla incidents into its internal bug tracker and considered that deliverable complete.
- Mozilla representative — Mozilla staff said the bug seemed ready to be closed and planned to schedule closure.