← Google Trust Services LLC cases
Bugzilla #2032511 Ca Security Vulnerability Self Reported Incident

Google Trust Services: Short OCSP outage

RESOLVED FIXED Google Trust Services LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Google Trust Services (GTS) reported that its OCSP responders experienced an outage for approximately two hours, during which certificate status requests returned HTTP 503 errors. GTS stated the outage was caused by an access control configuration error during a migration to consolidate and improve access control group management, which unintentionally denied data read permissions needed by the OCSP responder service. GTS said no certificates were impacted and that issuance was not stopped because the outage affected only retrieval of status information, not certificate validity. GTS identified the root cause as a lack of staged rollouts for legacy groups used by the OCSP service, along with incomplete dependency visibility and over-reliance on automated safety checks. GTS resolved the incident by rolling back the configuration change and re-enabling the necessary access control groups so OCSP responders resumed serving valid status information. In the thread, GTS also reported completing remediation actions including enabling “production-critical” protections for OCSP-related access groups, auditing production workloads for similar access control configurations, and implementing a policy to verify critical access control changes in test/staging before applying to production. The bug was resolved as FIXED, with GTS requesting closure after stating all action items were completed.

Model: gpt-5.4-nano Generated: 2026-06-13 21:38 UTC Revised: 2026-06-16 18:53 UTC Confidence: 0.90 7 comments
Chronology
  1. GTS OCSP responders returned HTTP 503 errors for about two hours due to an access control configuration error during an access control migration.
  2. GTS published a public full incident report attachment for the Bugzilla case.
  3. GTS reported incident closure summary and stated remediation actions were completed.
  4. Mozilla CA Program bug status reached RESOLVED with resolution FIXED.
Thread Activity
  1. Google representative — GTS submitted a preliminary incident report stating the OCSP outage lasted about two hours, was caused by an access control issue, and that it would publish a full incident report by 2026-04-30 while requesting nextUpdate be set to then.
  2. Google representative — GTS added a public incident report attachment for the bug.
  3. Google representative — GTS corrected the bug by stating it mistakenly re-added the needInfo flag and that the flag should be removed.
  4. Google representative — GTS provided an action-item table and stated the remaining action items were completed, requesting nextUpdate be set to 2026-05-22.
  5. Google representative — GTS posted a report closure summary describing the incident, root causes, remediation, and commitment that all action items were completed, requesting closure.
  6. CCADB representative — CCADB posted a final call for comments/questions and stated the bug would be closed around 2026-05-29.
Participants
Google representative CCADB representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1979457 RESOLVED Self Reported Incident Opened 2025-07-25 · Closed 2025-10-22 · 96% similar
Google Trust Services: Missing authorization audit log entry for certificate issuance
#2017747 RESOLVED Self Reported Incident Opened 2026-02-18 · Closed 2026-04-30 · 87% similar
Google Trust Services: Outdated BR version in some validation records
#1630040 RESOLVED Self Reported Incident Opened 2020-04-14 · Closed 2023-02-22 · 81% similar
Google Trust Services: OCSP serving issue 2020-04-09
#1630079 RESOLVED Self Reported Incident Opened 2020-04-14 · Closed 2023-02-22 · 80% similar
Google Trust Services: Invalid OCSP responses
#1793467 RESOLVED Ca Security Vulnerability Opened 2022-10-03 · Closed 2023-02-22 · 80% similar
Google Trust Services: invalid CRL reason code
#1815874 RESOLVED Self Reported Incident Opened 2023-02-09 · Closed 2023-03-20 · 79% similar
Google Trust Services: incorrect SCT in certificate
#1522975 RESOLVED Ca Security Vulnerability Incident Opened 2019-01-25 · Closed 2023-02-22 · 78% similar
Google Trust Services: Improper OCSP response for intermediate certificate
#1770510 RESOLVED Self Reported Incident Opened 2022-05-20 · Closed 2023-05-04 · 78% similar
Google Trust Services: Failure to provide preliminary report within 24h

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action