← Google Trust Services LLC cases
Bugzilla #1873739 Policy Document Issue

Google Trust Services: uses "DNSSec-mostly" and DTPs for DNS resolution

RESOLVED INVALID Google Trust Services LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case involves Google Trust Services (GTS) and its use of Google Public DNS and Cloudflare as DNS resolvers for domain validation. Concerns were raised regarding whether GTS's reliance on these services constituted the use of a Delegated Third Party (DTP) and whether it complied with the CA/Browser Forum's Baseline Requirements. GTS clarified that it operates its own DNSSEC validator and does not consider Google Public DNS a DTP, as its usage is within the scope of its WebTrust audit. The case was ultimately resolved as invalid, with the conclusion that GTS's practices did not violate the Baseline Requirements.

Model: gpt-4o-mini Generated: 2026-06-13 21:34 UTC Revised: 2026-06-16 18:48 UTC Confidence: 0.85 29 comments
Chronology
  1. Bug created regarding GTS's DNS validation practices.
  2. Case closed as invalid after GTS's clarifications.
Thread Activity
  1. Ltri representative — Created attachment detailing DNS validation concerns.
  2. Google representative — GTS explained its DNS validation process and addressed DTP concerns.
  3. Mozilla representative — Indicated intention to close the case as invalid.
  4. Mozilla representative — Confirmed closure of the case as invalid.
Participants
Community commenter
External References
Similar Local Cases
#1705480 RESOLVED Ca Documents Policy Document Issue Opened 2021-04-15 · Closed 2023-02-22 · 59% similar
SECOM: CP/CPS does not clearly specify domain validation methods
#1688215 RESOLVED Ca Documents Incident Policy Document Issue Opened 2021-01-22 · Closed 2023-02-22 · 58% similar
Camerfirma: CP/CPS of Intesa Sanpaolo Sub-CA is Non-Compliant
#1693930 RESOLVED Policy Document Issue Opened 2021-02-20 · Closed 2023-02-22 · 58% similar
Microsoft PKI Services: Policy Documentation, Failure to update Subscriber Certificate Max Validity Period
#1705904 RESOLVED Policy Document Issue Self Reported Incident Opened 2021-04-17 · Closed 2023-02-22 · 58% similar
KIR S.A.: CP/CPS contains noncompliant DV method, does not specify CAA domains
#1596949 RESOLVED Ca Documents Policy Document Issue Self Reported Incident Opened 2019-11-15 · Closed 2023-02-22 · 58% similar
FNMT: CP/CPS lack CAA processing details
#1973341 RESOLVED Policy Document Issue Certificate Misissuance Opened 2025-06-21 · Closed 2025-08-19 · 58% similar
eMudhra emSign PKI Services: Policy Document Inconsistency
#1771727 RESOLVED Audit Finding Policy Document Issue Opened 2022-05-30 · Closed 2023-02-22 · 58% similar
Firmaprofesional: 2022 - Define Device Obsolescence Process
#1713976 RESOLVED Policy Document Issue Opened 2021-06-02 · Closed 2023-02-22 · 58% similar
Amazon Trust Services: CP/CPS does not specify key compromise methods

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action