← Google Trust Services LLC cases
Bugzilla #1706967 Certificate Problem Report

Google Trust Services: Forbidden Domain Validation Method 3.2.2.4.10

RESOLVED FIXED Google Trust Services LLC
AI Summary

Google Trust Services (GTS) was reported for using a forbidden domain validation method as outlined in their Certificate Policy Statement (CPS). The method in question, which was still referenced in their CPS, was retired under the Baseline Requirements. GTS acknowledged the issue and initiated an incident report, confirming that they had not used the deprecated method since September 2020. They subsequently updated their CPS to reflect the correct validation method and began revocation of affected certificates. The incident involved over a million certificates, and GTS has committed to monitoring and improving their compliance processes.

Model: gpt-4o-mini Generated: 2026-06-13 21:24 UTC Confidence: 0.95
Chronology
  1. Mozilla Bug 1706967 is filed.
  2. GTS CPS is updated to remove the forbidden validation method.
  3. Re-issuance and revocation of affected certificates begins.
  4. GTS shares the incident report.
Participants
Andrew Ayer Andy Warner Doughornyak Ryan Sleevi
Similar Local Cases
#1634795 RESOLVED Certificate Problem Report Opened 2020-05-01 · Closed 2023-02-22 · 67% similar
Google Trust Services: Incorrect revocation data temporarily served for GTS Y3 & Y4
#1630040 RESOLVED Certificate Problem Report Opened 2020-04-14 · Closed 2023-02-22 · 66% similar
Google Trust Services: OCSP serving issue 2020-04-09
#1630079 RESOLVED Certificate Problem Report Opened 2020-04-14 · Closed 2023-02-22 · 66% similar
Google Trust Services: Invalid OCSP responses
#1678183 RESOLVED Certificate Problem Report Opened 2020-11-19 · Closed 2023-02-22 · 64% similar
Google Trust Services: Invalid ASN.1 encoding of singleExtensions in OCSP responses
#1716163 RESOLVED Certificate Problem Report Opened 2021-06-12 · Closed 2024-05-25 · 61% similar
e-commerce monitoring GmbH: Revoked test website not using revoked certificate
#1793467 RESOLVED Certificate Problem Report Opened 2022-10-03 · Closed 2023-02-22 · 60% similar
Google Trust Services: invalid CRL reason code
#1715421 RESOLVED Certificate Problem Report Opened 2021-06-09 · Closed 2023-02-22 · 60% similar
Google Trust Services: Failure to revoke subscriber certificates within BR timeframe
#1581183 RESOLVED Certificate Problem Report Opened 2019-09-13 · Closed 2023-02-22 · 60% similar
Google Trust Services: CRL handling of expired certificates not fully compliant with RFC 5280 Section 3.3

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action