← Google Trust Services LLC cases
Bugzilla #1731164 Incident

Google Trust Services: CRL validity period set to expected value plus one second

RESOLVED FIXED Google Trust Services LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Google Trust Services reported a preliminary incident involving the validity period of CRLs used by its secondary CA system running EJBCA. The issue was identified on 2021-09-10 16:04 UTC during a periodic review by a Compliance Engineer, who found the CRL validity period configured as 10 days but potentially resulting in an actual validity period of 10 days plus one second due to EJBCA configuration. The CA stated that RFC 5280 makes the CRL next update field inclusive of the final second, and that while the Baseline Requirements do not explicitly state CRL validity duration in the same inclusive way, Google believed the behavior was against the spirit of the BRs. Google deployed a fix on 2021-09-10 21:53 UTC and deployed it to all systems by 2021-09-16 18:32 UTC, publishing new CRLs on 2021-09-10 20:45 UTC. The CA stated the issue did not result in misissuance of certificates and that certificate issuance was not stopped. Google later reported that remediation steps were completed and requested the bug be marked Fixed; Mozilla indicated it would schedule closure, and the bug is resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:28 UTC Revised: 2026-06-16 18:42 UTC Confidence: 0.86 7 comments
Chronology
  1. Google Trust Services identified that CRL validity periods on its secondary EJBCA system could be 10 days plus one second and initiated remediation.
  2. Google Trust Services published new CRLs after deploying a fix to correct the CRL validity period.
  3. Google Trust Services completed deployment of the CRL validity period fix across all systems.
  4. Google Trust Services reported remediation completion and requested the bug be marked Fixed.
  5. Mozilla scheduled closure of the bug (per comment indicating closure next Wed).
Thread Activity
  1. Google representative — Opened a preliminary incident report describing discovery of CRL validity period being 10 days plus one second, the rationale, and that a fix was deployed and new CRLs were published.
  2. Google representative — Provided a detailed incident timeline and explanation, including that the issue did not result in misissuance and that remediation was underway/completed as of the patch deployment.
  3. Google representative — Stated Google Trust Services was monitoring the bug for additional updates or questions.
  4. Google representative — Stated Google Trust Services was monitoring the bug for additional updates or questions.
  5. Google representative — Stated Google Trust Services was monitoring the bug for additional updates or questions.
  6. Google representative — Reported completion of remediation steps, said no community concerns were raised, and asked Mozilla to advise on marking the bug as Fixed, referencing guidance and a CABF draft ballot.
  7. Mozilla representative — Responded that Mozilla would schedule closure next Wednesday (20-Oct-2021).
Participants
Google representative Mozilla representative
Similar Local Cases
#1708516 RESOLVED Incident Opened 2021-04-29 · Closed 2023-02-22 · 96% similar
Google Trust Services: Failure to provide regular and timely incident updates
#1758372 RESOLVED Incident Opened 2022-03-07 · Closed 2023-02-22 · 95% similar
Google Trust Services: Incorrect OCSP response for issued certificate
#1948368 RESOLVED Incident Opened 2025-02-14 · Closed 2025-03-14 · 89% similar
Google Trust Services: Self-audit tooling MPIC perspective verification inconsistency
#1931413 RESOLVED Incident Opened 2024-11-14 · Closed 2024-12-27 · 88% similar
Google Trust Services: New hire onboarding deviation from written procedure
#1959867 RESOLVED Incident Opened 2025-04-11 · Closed 2025-06-10 · 81% similar
Google Trust Services: Inconsistent MPCAA secondary perspective logging
#1522975 RESOLVED Ca Security Vulnerability Incident Opened 2019-01-25 · Closed 2023-02-22 · 80% similar
Google Trust Services: Improper OCSP response for intermediate certificate
#1769222 RESOLVED Incident Opened 2022-05-13 · Closed 2024-06-30 · 71% similar
SECOM: Failed an annual CPS update of Cybertrust Japan (CTJ)
#1876775 RESOLVED Incident Opened 2024-01-26 · Closed 2024-03-04 · 70% similar
Sectigo: Wrong usage of LEI records for the issuance of SMIME Certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action