← Google Trust Services LLC cases
Bugzilla #1706967 Self Incident Disclosure

Google Trust Services disclosed a CPS documentation error involving TLS-ALPN validation method references

RESOLVED FIXED Google Trust Services LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns Google Trust Services (GTS) disclosing that its CPS still referenced Baseline Requirements domain validation method 3.2.2.4.10 after that method had been retired and replaced by TLS-ALPN. The issue was first raised by Andrew Ayer, who pointed out that the CPS text described a forbidden validation method. GTS acknowledged the report, prepared an incident report, updated its CPS to remove the outdated reference and add the current method, and said it reviewed its configurations and confirmed TLS-ALPN was the only random-number-based validation method it had used since 2020-09-22. GTS also stated that revocation was needed, re-issuance began and completed on 2021-05-01, and revocation of the associated certificates completed the same day. The thread later notes that GTS implemented tooling to mirror relevant Mozilla Bugzilla incidents into its internal tracking system. The bug was ultimately resolved FIXED, and Mozilla staff indicated it seemed ready to be closed.

Model: gpt-5.4-mini Generated: 2026-06-13 21:24 UTC Revised: 2026-06-16 18:38 UTC Confidence: 0.95 34 comments
Chronology
  1. Baseline Requirements version 1.7.3 took effect and removed method 10, replacing it with method 20 for TLS-ALPN.
  2. Mozilla Bug 1706967 was filed about GTS CPS text referencing the retired validation method.
  3. GTS updated its CPS to remove method 10 and add method 20.
  4. Associated certificates were re-issued and revoked.
  5. GTS said it had deployed tooling to mirror Mozilla Bugzilla incidents into its internal tracking system.
Thread Activity
  1. Mm representative — Andrew Ayer reported that GTS's CPS still described forbidden BR method 3.2.2.4.10.
  2. Google representative — GTS acknowledged the report and said an incident report was being prepared.
  3. Community commenter — GTS attached an incident report describing the timeline, affected certificates, and remediation steps.
  4. Community commenter — Ryan Sleevi questioned the adequacy and accuracy of the incident report and raised concerns about GTS's compliance processes.
  5. Google representative — GTS said it was preparing a new report to address the concerns.
  6. Google representative — GTS submitted a revised incident report with an updated timeline and certificate details.
  7. Community commenter — Ryan Sleevi said the revised report still did not sufficiently identify the root causes.
  8. Google representative — GTS said it had implemented tooling to mirror Mozilla Bugzilla incidents into its internal bug tracker and considered that deliverable complete.
  9. Mozilla representative — Mozilla staff said the bug seemed ready to be closed and planned to schedule closure.
Participants
Mm representative Google representative Community commenter Thisisntrocket representative Mozilla representative
Similar Local Cases
#1708516 RESOLVED Incident Opened 2021-04-29 · Closed 2023-02-22 · 74% similar
Google Trust Services: Failure to provide regular and timely incident updates
#1709223 RESOLVED Certificate Misissuance Opened 2021-05-03 · Closed 2023-02-22 · 69% similar
Google Trust Services: Signing SHA-1 Hash for existing CA certificate with changes in Key Usage
#1758372 RESOLVED Incident Opened 2022-03-07 · Closed 2023-02-22 · 69% similar
Google Trust Services: Incorrect OCSP response for issued certificate
#1793467 RESOLVED Ca Security Vulnerability Opened 2022-10-03 · Closed 2023-02-22 · 61% similar
Google Trust Services: invalid CRL reason code
#1630040 RESOLVED Self Reported Incident Opened 2020-04-14 · Closed 2023-02-22 · 60% similar
Google Trust Services: OCSP serving issue 2020-04-09
#1630079 RESOLVED Self Reported Incident Opened 2020-04-14 · Closed 2023-02-22 · 60% similar
Google Trust Services: Invalid OCSP responses
#1612389 RESOLVED Certificate Misissuance Opened 2020-01-30 · Closed 2023-02-22 · 59% similar
Google Trust Services: invalid curve-hash combination
#1729097 RESOLVED Repository Issue Opened 2021-09-03 · Closed 2023-02-22 · 59% similar
Google Trust Services: Delayed publication of CPS removing DNS Operator Exception

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action