← Google Trust Services LLC cases
Bugzilla #1959867
Certificate Problem Report
Google Trust Services: Inconsistent MPCAA secondary perspective logging
RESOLVED
FIXED
Google Trust Services LLC
AI Summary
Google Trust Services (GTS) identified an issue with the logging of Multi-Perspective Certificate Authority Authorization (MPCAA) checks, affecting approximately 1.5% of results. This incident was self-discovered through automated audits, leading to a temporary halt in certificate issuance to expedite mitigation. The root causes included unexpected non-routable IP addresses and DNS resolution timeouts. GTS has since implemented fixes and improved monitoring to prevent recurrence, ensuring compliance with relevant policies.
Chronology
- Non-compliance start date
- Non-compliance identified
- Non-compliance ended and issuance resumed
- Report closure summary issued
- Final call for comments on incident report
Participants
gts-external@google.com
daknob@daknob.net
amir@aaomidi.com
jrmoir@protonmail.com
External References
Similar Local Cases
Google Trust Services: SXG certificates issued without correctly checking CAA restrictions
Google Trust Services: OCSP serving issue 2020-04-09
Buypass: Domain validation method using externally operated DNS tools
Google Trust Services: Missing authorization audit log entry for certificate issuance
Google Trust Services: Short OCSP outage
Google Trust Services: Outdated BR version in some validation records
Google Trust Services: incorrect SCT in certificate
Google Trust Services: Improper OCSP response for intermediate certificate