← Google Trust Services LLC cases
Bugzilla #1793467
Certificate Problem Report
Google Trust Services: invalid CRL reason code
RESOLVED
FIXED
Google Trust Services LLC
AI Summary
A report was filed regarding an invalid CRL reason code used by Google Trust Services, which violated RFC 5280. The issue stemmed from a bug in the library used to generate revocation reason codes, leading to incorrect mappings. Google Trust Services promptly investigated the issue, identified the bug, and deployed a fix. The affected CRL was republished with the correct reason code, and the CA continued issuing certificates as no misissued certificates were involved.
Chronology
- Incident reported by Andrew Ayer.
- Bug identified and fix submitted.
- Deployment of the fix concluded.
Participants
Andrew Ayer
Cade Cairns
External References
Similar Local Cases
Google Trust Services: incorrect SCT in certificate
Google Trust Services: Forbidden Domain Validation Method 3.2.2.4.10
Google Trust Services: Incorrect OCSP response for issued certificate
Google Trust Services: Incorrect OCSP responses for certain certificates
Google Trust Services: Failure to provide preliminary report within 24h
Google Trust Services: Failure to respond to CPR within 24 hours
Google Trust Services: Incorrect revocation data temporarily served for GTS Y3 & Y4
Google Trust Services: Failure to properly validate IP address