← Google Trust Services LLC cases
Bugzilla #1706976 Ca Documents

Google Trust Services: Out-of-date CPS disclosure

RESOLVED INVALID Google Trust Services LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The case concerns Google Trust Services (GTS) having an out-of-date CPS disclosure in the Common CA Database (CCADB). The CCADB record indicated the root operates under a CPS versioned v2.22 dated 2020-08-21, with the CPS URL https://pki.goog/repo/cps/2.22/GTS-CPS.pdf. However, https://pki.goog publishes a newer CPS versioned v3.0 dated 2021-03-19 at https://pki.goog/repo/cps/3.0/GTS-CPS.pdf, which was described as a violation of CCADB Policy Section 5 requiring CPS URLs to be updated as new information becomes available. GTS acknowledged the report, and Mozilla staff noted that an incident report was being prepared with full details. Mozilla later stated that CAs cannot update their CPs and CPSes in CCADB without additional intervention from the root store member of CCADB. The Mozilla staff member then indicated they had updated/corrected the CCADB record and marked the bug as invalid.

Model: gpt-5.4-nano Generated: 2026-06-13 21:25 UTC Revised: 2026-06-16 18:39 UTC Confidence: 0.86 4 comments
Chronology
  1. A CCADB compliance issue was reported regarding an out-of-date CPS URL for a GTS root.
  2. GTS acknowledged the report and Mozilla indicated an incident report was being prepared.
  3. Mozilla corrected the CCADB record and marked the bug invalid.
Thread Activity
  1. Mm representative — Reported that CCADB listed GTS CPS v2.22 (2020-08-21) but https://pki.goog publishes a newer CPS v3.0 (2021-03-19), citing a CCADB Policy Section 5 violation.
  2. Google representative — Acknowledged the report and said other roots were updated in CCADB on March 25, with an incident report being prepared for the GS R2 update.
  3. Mozilla representative — Stated that CAs cannot update their CPs and CPSes in CCADB without additional intervention from the root store member.
  4. Mozilla representative — Said this may have been an oversight, that the CCADB record was updated/corrected, and marked the bug as invalid.
Participants
Mm representative Google representative Mozilla representative
Similar Local Cases
#1667844 RESOLVED Ca Documents Opened 2020-09-28 · Closed 2023-02-22 · 96% similar
Google Trust Services: Certificates not disclosed in CCADB
#1941675 RESOLVED Ca Documents Incident Opened 2025-01-14 · 73% similar
Certum root lists a Microsec CPS in AllCertificateRecordsCSVFormatv2
#1812336 RESOLVED Ca Documents Opened 2023-01-25 · Closed 2023-02-10 · 67% similar
Sectigo: Late CCADB update after CPS update
#2028195 RESOLVED Ca Documents Opened 2026-03-31 · Closed 2026-04-11 · 67% similar
GoDaddy: inconsistent CP/CPS disclosure
#1814197 RESOLVED Ca Documents Opened 2023-01-31 · Closed 2023-02-14 · 67% similar
DigiCert: Late CP/CPS CCADB uploads
#1667846 RESOLVED Ca Documents Incident Opened 2020-09-28 · Closed 2022-11-14 · 67% similar
Izenpe: Certificates not disclosed in CCADB
#1716351 RESOLVED Ca Documents Audit Document Remediation Tracking Opened By Root Store Opened 2021-06-14 · Closed 2026-06-25 · 64% similar
HARICA: Audit Documents
#1626805 RESOLVED Ca Documents Audit Finding Opened 2020-04-01 · Closed 2023-02-22 · 64% similar
FNMT: Minor non-conformities in 2020 audit statement

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action