← Google Trust Services LLC cases
Bugzilla #1815874
Self Reported Incident
Google Trust Services: incorrect SCT in certificate
RESOLVED
FIXED
Google Trust Services LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
Google Trust Services (GTS) discovered that a certificate it issued contained incorrect Signed Certificate Timestamps (SCTs) that did not match the corresponding precertificate. This issue was identified when a user reported the problem, prompting GTS to investigate. They confirmed that the SCTs were invalid and ceased issuance of SignedHTTPExchange (SXG) certificates. GTS has since revoked the affected certificates and implemented a fix to prevent future occurrences. A full report detailing the incident and corrective actions is expected to be published.
Chronology
- GTS discovers incorrect SCTs in issued certificate.
- GTS revokes the problematic certificate.
- GTS revokes remaining affected certificates.
- GTS resumes issuance of SXG certificates after fixing the bug.
Thread Activity
- Mm representative — Reported incorrect SCTs in a certificate issued by GTS.
- Google representative — GTS is investigating the issue.
- Google representative — Confirmed SCTs are invalid and ceased issuance of SXG certificates.
- Google representative — Revocation of the problematic certificates has started.
- Google representative — GTS verified that the bug can be caught using Go's Data Race Detector.
- Google representative — GTS requests consideration to close the bug.
Participants
Community commenter
External References
Similar Local Cases
Google Trust Services: Missing authorization audit log entry for certificate issuance
Google Trust Services: Failure to provide preliminary report within 24h
Google Trust Services: OCSP serving issue 2020-04-09
Google Trust Services: Short OCSP outage
Google Trust Services: Invalid OCSP responses
Google Trust Services: Outdated BR version in some validation records
Entrust: SHA-256 hash algorithm used with ECC P-384 key
Let's Encrypt: TLS Using ALPN Allows Additional Identifiers in Challenge Certificate