← Google Trust Services LLC cases
Bugzilla #1709223 Certificate Misissuance

Google Trust Services reissued a root CA certificate with SHA-1 after a key-usage compliance change

RESOLVED FIXED Google Trust Services LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Google Trust Services opened this case to disclose a root CA certificate reissuance tied to a key-usage compliance fix from Bug 1652581. GTS said it identified the SHA-1 issue during internal discussion about how to modify the root certificate, then consulted auditors and root-program contacts before reissuing the certificate on 2020-08-13 with its original SHA-1 signature algorithm. The thread focuses on whether that reissuance was compatible with Mozilla Root Store Policy, especially section 5.1.3, and on what communications and research informed GTS's decision. GTS later said it had disclosed the issue to its auditors, would take future interpretation questions to mozilla.dev.security.policy, and had implemented the remediation items unique to this response. Mozilla participants continued to question the adequacy of the explanation and the completeness of the remediation, but the bug was ultimately resolved and Mozilla stated it would not include the re-signed R2 CA certificate in GTS's pending inclusion request.

Model: gpt-5.4-mini Generated: 2026-06-13 21:26 UTC Revised: 2026-06-16 18:40 UTC Confidence: 0.93 41 comments
Chronology
  1. GTS identified a key-usage profile issue with a root certificate profile.
  2. GTS received confirmation from auditors that they believed the change was allowed.
  3. Google Trust Services reissued the root CA certificate using its original SHA-1 signature algorithm.
  4. GTS opened the Mozilla bug to disclose the SHA-1 root certificate reissuance.
  5. GTS said it had implemented all remediation items unique to this response.
Thread Activity
  1. Community commenter — GTS described how it discovered the SHA-1 issue during work on the root certificate modification and provided the initial incident timeline.
  2. Mm representative — Mozilla asked GTS about its policy research, its awareness of MRSP section 5.1.3, and what it disclosed to Mozilla.
  3. Community commenter — GTS explained why it believed the MRSP language was unclear and why it sought confirmation from Mozilla and auditors.
  4. Community commenter — GTS said it had disclosed all known compliance issues to its auditors and expected the audit report to include relevant facts.
  5. Google representative — GTS reiterated that it had disclosed the issues to auditors and said it would answer further questions.
  6. Google representative — GTS said it would expand engineering participation in compliance review and take future interpretation conversations to mdsp.
  7. Mozilla representative — Mozilla said the bug could be closed and planned to review it again on 2021-06-04.
  8. Google representative — GTS said it had implemented all items in its remediation plan unique to this response.
  9. Mozilla representative — Mozilla said it would close the bug on or about 2021-07-30 unless there were reasons to keep it open.
Participants
Community commenter Mm representative Thisisntrocket representative Google representative Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1612389 RESOLVED Certificate Misissuance Opened 2020-01-30 · Closed 2023-02-22 · 88% similar
Google Trust Services: invalid curve-hash combination
#1902670 RESOLVED Certificate Misissuance Revocation Issue Opened 2024-06-14 · Closed 2024-07-31 · 85% similar
Google Trust Services: SXG certificates issued without correctly checking CAA restrictions
#1711432 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-05-17 · Closed 2023-02-22 · 83% similar
Telekom Security: Certificate with invalid FQDN
#1672423 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2020-10-21 · Closed 2023-02-22 · 82% similar
Camerfirma: certificate for unregistered domain cuatis.net
#1712188 RESOLVED Certificate Misissuance Opened 2021-05-20 · Closed 2023-02-22 · 82% similar
Sectigo: test certificates issued from trusted CA
#1705187 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-04-14 · Closed 2023-02-22 · 82% similar
KIR S.A.: CN domain not in SAN
#1651026 RESOLVED Certificate Misissuance Incident Remediation Tracking Opened 2020-07-07 · Closed 2023-02-22 · 82% similar
Izenpe: certificate issued to internal domain
#1744827 RESOLVED Certificate Misissuance Delayed Revocation Opened 2021-12-07 · Closed 2024-03-08 · 82% similar
Entrust: SSL Certificates issued with Un-verified IP Addresses

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action