← Google Trust Services LLC cases
Bugzilla #1793467
Ca Security Vulnerability
Google Trust Services: invalid CRL reason code
RESOLVED
FIXED
Google Trust Services LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
Google Trust Services (GTS) was made aware of an invalid Certificate Revocation List (CRL) reason code reported by Andrew Ayer. The issue stemmed from a bug in the library used to generate CRLs, which caused an incorrect mapping of revocation reason codes. GTS investigated the incident, identified the bug, and deployed a fix. They confirmed that no misissued certificates resulted from this issue and the affected CRL was republished with the correct reason code. The case is now resolved with the necessary remediations implemented.
Chronology
- GTS received a report about an invalid CRL reason code.
- GTS deployed a fix to correct the CRL reason code mapping.
- The bug was marked as resolved.
Thread Activity
- Mm representative — Reported an invalid CRL reason code in a certificate issued by GTS.
- Google representative — Acknowledged the report and stated that GTS is investigating.
- Google representative — Provided a timeline of actions taken in response to the incident.
- Google representative — Committed to help push through CRL linting support for ZLint.
- Mozilla representative — Indicated plans to close the bug.
Participants
Mm representative
Google representative
Internet Security Research Group
Mozilla representative
External References
Similar Local Cases
Google Trust Services: Incorrect OCSP responses for certain certificates
Google Trust Services: Improper OCSP response for intermediate certificate
Google Trust Services: Short OCSP outage
TWCA: "unknown" OCSP response for issued certificates
GoDaddy: Intermittent unauthorized OCSP response when certificate is freshly issued
Google Trust Services: Incorrect OCSP response for issued certificate
DigiCert: OCSP responder returning invalid responses
DigiCert: Issuance of certs with weak keys (ROCA)