Google Trust Services: Self-audit tooling MPIC perspective verification inconsistency
Google Trust Services (GTS) disclosed an incident involving its custom self-auditing tool used to satisfy section 8.7 of the CA/B Baseline Requirements. GTS reported that the tool could verify MPIC perspective details incorrectly by using the first successful validation record found, even when that record corresponded to a corroborating perspective rather than the primary perspective. GTS stated that it detected the bug while preparing for MPIC requirements that became effective on March 15, 2025, and submitted a patch shortly after detection. GTS performed historical analysis using the patched tool and also ran historical checks for the last two years, reporting that neither run found any improper validation or mis-issuance issues. GTS stated there was no impact to issued certificates and that no revocations were necessary. In later comments, GTS reported completion of action items including fixing the self-auditing tool, adding automated submission checks for audit log format changes, and verifying that past audit log format updates did not require corresponding tool updates. Mozilla indicated it would review and close the bug, and GTS requested closure after confirming no further comments were expected.
- GTS detected a bug in its self-auditing tool while preparing to add support for MPIC requirements.
- GTS published a preliminary incident report in Bugzilla.
- GTS completed reruns of historical checks using the patched tool and custom validation, reporting no violations.
- GTS provided a report closure summary and requested closure.
- The bug was resolved as FIXED.
- Google representative — GTS described investigating a deviation in its self-audit tooling for MPIC perspective verification and said it had fixed incorrect code and would provide a full incident report by 2025-02-25.
- Google representative — GTS posted the incident report, stating the self-audit tool accepted a corroborating perspective as authoritative in some cases, and reported no impact to issued certificates after historical analysis.
- Google representative — GTS reported completion of remaining action items, including adding automated submission checks and verifying past audit log format updates.
- Google representative — GTS provided a report closure summary, requested closure, and stated all disclosed action items were completed.
- Mozilla representative — Mozilla stated it would review the bug on 12-Mar-2025 and close it unless further discussion was needed.
- Google representative — GTS requested closure if there were no further comments or questions.