← Google Trust Services LLC cases
Bugzilla #1948368 Incident

Google Trust Services: Self-audit tooling MPIC perspective verification inconsistency

RESOLVED FIXED Google Trust Services LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Google Trust Services (GTS) disclosed an incident involving its custom self-auditing tool used to satisfy section 8.7 of the CA/B Baseline Requirements. GTS reported that the tool could verify MPIC perspective details incorrectly by using the first successful validation record found, even when that record corresponded to a corroborating perspective rather than the primary perspective. GTS stated that it detected the bug while preparing for MPIC requirements that became effective on March 15, 2025, and submitted a patch shortly after detection. GTS performed historical analysis using the patched tool and also ran historical checks for the last two years, reporting that neither run found any improper validation or mis-issuance issues. GTS stated there was no impact to issued certificates and that no revocations were necessary. In later comments, GTS reported completion of action items including fixing the self-auditing tool, adding automated submission checks for audit log format changes, and verifying that past audit log format updates did not require corresponding tool updates. Mozilla indicated it would review and close the bug, and GTS requested closure after confirming no further comments were expected.

Model: gpt-5.4-nano Generated: 2026-06-13 21:36 UTC Revised: 2026-06-16 18:51 UTC Confidence: 0.90 6 comments
Chronology
  1. GTS detected a bug in its self-auditing tool while preparing to add support for MPIC requirements.
  2. GTS published a preliminary incident report in Bugzilla.
  3. GTS completed reruns of historical checks using the patched tool and custom validation, reporting no violations.
  4. GTS provided a report closure summary and requested closure.
  5. The bug was resolved as FIXED.
Thread Activity
  1. Google representative — GTS described investigating a deviation in its self-audit tooling for MPIC perspective verification and said it had fixed incorrect code and would provide a full incident report by 2025-02-25.
  2. Google representative — GTS posted the incident report, stating the self-audit tool accepted a corroborating perspective as authoritative in some cases, and reported no impact to issued certificates after historical analysis.
  3. Google representative — GTS reported completion of remaining action items, including adding automated submission checks and verifying past audit log format updates.
  4. Google representative — GTS provided a report closure summary, requested closure, and stated all disclosed action items were completed.
  5. Mozilla representative — Mozilla stated it would review the bug on 12-Mar-2025 and close it unless further discussion was needed.
  6. Google representative — GTS requested closure if there were no further comments or questions.
Participants
Google representative Mozilla representative
External References
Similar Local Cases
#1931413 RESOLVED Incident Opened 2024-11-14 · Closed 2024-12-27 · 95% similar
Google Trust Services: New hire onboarding deviation from written procedure
#1731164 RESOLVED Incident Opened 2021-09-16 · Closed 2023-02-22 · 89% similar
Google Trust Services: CRL validity period set to expected value plus one second
#1959867 RESOLVED Incident Opened 2025-04-11 · Closed 2025-06-10 · 88% similar
Google Trust Services: Inconsistent MPCAA secondary perspective logging
#1708516 RESOLVED Incident Opened 2021-04-29 · Closed 2023-02-22 · 87% similar
Google Trust Services: Failure to provide regular and timely incident updates
#1758372 RESOLVED Incident Opened 2022-03-07 · Closed 2023-02-22 · 86% similar
Google Trust Services: Incorrect OCSP response for issued certificate
#1522975 RESOLVED Ca Security Vulnerability Incident Opened 2019-01-25 · Closed 2023-02-22 · 78% similar
Google Trust Services: Improper OCSP response for intermediate certificate
#1876775 RESOLVED Incident Opened 2024-01-26 · Closed 2024-03-04 · 70% similar
Sectigo: Wrong usage of LEI records for the issuance of SMIME Certificates
#1909948 RESOLVED Incident Opened 2024-07-25 · Closed 2024-10-31 · 70% similar
GoDaddy: Edge Case for Data Reuse Outside of Timeframes

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action