← Google Trust Services LLC cases
Bugzilla #1793467 Ca Security Vulnerability

Google Trust Services: invalid CRL reason code

RESOLVED FIXED Google Trust Services LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Google Trust Services (GTS) was made aware of an invalid Certificate Revocation List (CRL) reason code reported by Andrew Ayer. The issue stemmed from a bug in the library used to generate CRLs, which caused an incorrect mapping of revocation reason codes. GTS investigated the incident, identified the bug, and deployed a fix. They confirmed that no misissued certificates resulted from this issue and the affected CRL was republished with the correct reason code. The case is now resolved with the necessary remediations implemented.

Model: gpt-4o-mini Generated: 2026-06-13 21:32 UTC Revised: 2026-06-16 18:46 UTC Confidence: 0.85 11 comments
Chronology
  1. GTS received a report about an invalid CRL reason code.
  2. GTS deployed a fix to correct the CRL reason code mapping.
  3. The bug was marked as resolved.
Thread Activity
  1. Mm representative — Reported an invalid CRL reason code in a certificate issued by GTS.
  2. Google representative — Acknowledged the report and stated that GTS is investigating.
  3. Google representative — Provided a timeline of actions taken in response to the incident.
  4. Google representative — Committed to help push through CRL linting support for ZLint.
  5. Mozilla representative — Indicated plans to close the bug.
Participants
Mm representative Google representative Internet Security Research Group Mozilla representative
External References
Similar Local Cases
#1773556 RESOLVED Ca Security Vulnerability Opened 2022-06-09 · Closed 2023-02-22 · 100% similar
Google Trust Services: Incorrect OCSP responses for certain certificates
#1522975 RESOLVED Ca Security Vulnerability Incident Opened 2019-01-25 · Closed 2023-02-22 · 83% similar
Google Trust Services: Improper OCSP response for intermediate certificate
#2032511 RESOLVED Ca Security Vulnerability Self Reported Incident Opened 2026-04-16 · Closed 2026-05-29 · 80% similar
Google Trust Services: Short OCSP outage
#1793445 RESOLVED Ca Security Vulnerability Remediation Tracking Opened 2022-10-03 · Closed 2023-04-19 · 76% similar
TWCA: "unknown" OCSP response for issued certificates
#1905419 RESOLVED Ca Security Vulnerability Opened 2024-06-28 · Closed 2024-10-31 · 76% similar
GoDaddy: Intermittent unauthorized OCSP response when certificate is freshly issued
#1758372 RESOLVED Incident Opened 2022-03-07 · Closed 2023-02-22 · 70% similar
Google Trust Services: Incorrect OCSP response for issued certificate
#1662346 RESOLVED Ca Security Vulnerability Security Incident Opened 2020-09-01 · Closed 2023-02-22 · 68% similar
DigiCert: OCSP responder returning invalid responses
#1744795 RESOLVED Ca Security Vulnerability Security Incident Opened 2021-12-07 · Closed 2023-02-22 · 67% similar
DigiCert: Issuance of certs with weak keys (ROCA)

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action