← Google Trust Services LLC cases
Bugzilla #1838707
Certificate Problem Report
Google Trust Services: Revocation data publication delay for revoked unused subordinate CAs
RESOLVED
FIXED
Google Trust Services LLC
AI Summary
Google Trust Services identified a delay in publishing revocation data for several unused subordinate CAs that were revoked on June 13, 2023. The revocation information was not published within the required 24-hour timeframe, leading to an internal security event and subsequent investigation. The issue was resolved by implementing a linter to verify ceremony configurations and amending procedures to ensure timely publication of revocation data. All actions outlined in the incident report have been completed, and the CA has committed to maintaining consistent practices for future ceremonies.
Chronology
- Incident identified and internal investigation initiated.
- All corrective actions completed and procedures amended.
Participants
Nick Naziridis
Fritz Hochstrasser
Ben Wilson
External References
Similar Local Cases
Google Trust Services: Failure to respond to CPR within 24 hours
Google Trust Services: Invalid ASN.1 encoding of singleExtensions in OCSP responses
Google Trust Services: Missing authorization audit log entry for certificate issuance
Google Trust Services: Failure to revoke subscriber certificates within BR timeframe
Google Trust Services: Failure to provide preliminary report within 24h
Google Trust Services: Failure to properly validate IP address
TWCA: Undisclosed CA
Google Trust Services: Incorrect revocation data temporarily served for GTS Y3 & Y4