Google Trust Services: Outdated BR version in some validation records
Google Trust Services (GTS) self-identified an issue in which the Baseline Requirements (BR) version number recorded in some domain validation logs was not the BR version in effect at the time of validation. GTS stated that the domain control validation itself was performed correctly and remained compliant with the applicable BRs at the time, and that the problem was limited to the logged BR version number being stale. GTS paused certificate issuance while it evaluated the potential non-compliance, then implemented and deployed a code change to update the BR version being logged in validation logs; issuance was resumed after deployment. GTS reported that the first stale BR version was recorded starting on 2018-07-08 and that the non-compliance was identified on 2026-02-17 and ended on 2026-02-18. In its full incident report, GTS stated that the incident affected 0 certificates and that it requested closure after completing the disclosed action items. The thread also notes that GTS participated in community discussions and that the CA/B Forum passed Ballot SC-99 to clarify BR sections 3.2.2.4 and 3.2.2.5.
- GTS began recording a stale BR version number in domain validation logs.
- GTS identified the BR version logging non-compliance during internal checks.
- GTS ended the period of non-compliance after addressing the logging issue.
- GTS paused issuance and deployed a fix to log the correct BR version; issuance resumed.
- GTS posted a report closure summary and requested closure of the incident report.
- Google representative — GTS reported that an incorrect BR version number was recorded in a log set for domain validations, that validation processes were not affected, and that it stopped issuance while deploying a fix and then resumed issuance.
- Google representative — GTS posted a preliminary incident report, citing BR sections 3.2.2.4 and 3.2.2.5 and stating the disclosure was based on internal discovery from similar CA incidents.
- Google representative — GTS posted a full incident report with a timeline (including non-compliance start/end dates), stated impact as 0 certificates, and described that issuance was paused and then re-enabled after deploying a code change.
- Google representative — GTS noted discussions following CA/B Forum F2F meeting and a proposed ballot to clarify BR clause language, requesting a later nextUpdate date before closure.
- Google representative — GTS provided a report closure summary, describing the root causes, remediation steps (pause issuance, deploy logging fix, community participation), and requesting closure after action items were completed.
- CCADB representative — CCADB requested a final call for comments and stated the incident report would be closed approximately 2026-04-30.