← Google Trust Services LLC cases
Bugzilla #1715421
Certificate Problem Report
Google Trust Services: Failure to revoke subscriber certificates within BR timeframe
RESOLVED
FIXED
Google Trust Services LLC
AI Summary
Google Trust Services (GTS) faced issues with timely revocation of subscriber certificates following a non-compliance incident. The CA was informed on April 22, 2021, about the use of an unauthorized domain control validation method, yet the revocation was not completed until May 1, 2021, exceeding the required timeframe. GTS acknowledged the delay and attributed it to a failure in their process rather than human error. They have since implemented changes to improve their incident response and compliance processes to prevent future occurrences.
Chronology
- GTS informed of unauthorized domain control validation method.
- Revocation of affected certificates completed.
- Incident report filed to track delay in revocation.
Participants
Ryan Sleevi
Fotis Loukos
External References
Similar Local Cases
Google Trust Services: Forbidden Domain Validation Method 3.2.2.4.10
Google Trust Services: OCSP serving issue 2020-04-09
Google Trust Services: Incorrect revocation data temporarily served for GTS Y3 & Y4
Google Trust Services: Improper OCSP response for intermediate certificate
Google Trust Services: Invalid OCSP responses
Google Trust Services: Invalid ASN.1 encoding of singleExtensions in OCSP responses
Google Trust Services: Failure to send preliminary report to subscriber within 24h
Google Trust Services: Failure to provide preliminary report within 24h