← Google Trust Services LLC cases
Bugzilla #1979457
Certificate Problem Report
Google Trust Services: Missing authorization audit log entry for certificate issuance
RESOLVED
FIXED
Google Trust Services LLC
AI Summary
Google Trust Services (GTS) identified an issue where a certificate was issued without a corresponding authorization event being recorded in the audit log due to a race condition. This was detected by GTS's self-auditing tool, leading to the revocation of the affected certificate. GTS has implemented fixes to prevent similar occurrences in the future and has completed all action items related to this incident. The root cause was traced to an expired security token that exposed the race condition, and GTS has taken steps to enhance their logging and monitoring processes.
Chronology
- Certificate issued without audit log entry
- Issue detected by self-auditing tool
- Full incident report published
- Final action item completed
- Incident report closure expected
Participants
Google Trust Services
Mozilla CCADB
External References
Similar Local Cases
Google Trust Services: Self-audit tooling MPIC perspective verification inconsistency
Google Trust Services: Failure to properly validate IP address
Google Trust Services: Short OCSP outage
Google Trust Services: Outdated BR version in some validation records
Google Trust Services: Incorrect OCSP responses for new ICAs under test
Google Trust Services: OCSP serving issue 2020-04-09
Google Trust Services: Inconsistent MPCAA secondary perspective logging
Google Trust Services: Incorrect OCSP responses for certain certificates