← Google Trust Services LLC cases
Bugzilla #1876593
Certificate Problem Report
Google Trust Services: Failure to properly validate IP address
RESOLVED
FIXED
Google Trust Services LLC
AI Summary
Google Trust Services (GTS) encountered an issue with IP address validation, leading to the revocation of all affected certificates. The incident stemmed from a failure to properly validate a single IP address due to reliance on outdated manual processes. GTS has since implemented a series of corrective actions, including automating validation procedures and enhancing compliance monitoring. All action items related to this incident have been completed, and GTS continues to monitor for any further questions or comments.
Chronology
- Initial report of IP validation issue.
- Attachments of revoked and affected certificates created.
- Incident report published; immediate process changes implemented.
- Continual compliance monitoring enabled in production.
- GTS requests closure of the incident.
Participants
Google Trust Services
Mozilla
External References
Similar Local Cases
Google Trust Services: Self-audit tooling MPIC perspective verification inconsistency
Google Trust Services: Incorrect OCSP responses for new ICAs under test
Google Trust Services: Missing authorization audit log entry for certificate issuance
Google Trust Services: Outdated BR version in some validation records
Google Trust Services: Short OCSP outage
Google Trust Services: Forbidden Domain Validation Method 3.2.2.4.10
Google Trust Services: Failure to revoke subscriber certificates within BR timeframe
Google Trust Services: OCSP serving issue 2020-04-09