← Google Trust Services LLC cases
Bugzilla #2058261 Ca Documents Incident Self Reported Incident Policy Document Issue Remediation Tracking

Google Trust Services CP/CPS missing Chrome Root Program and CCADB policy attestation

ASSIGNED Google Trust Services LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Google Trust Services reported that its combined CP/CPS did not include an explicit statement confirming adherence to the Chrome Root Program Policy and the CCADB Policy by the June 15, 2026 effective date. The case was opened by Google Trust Services after a third-party report identified the missing statement. GTS said the non-compliance began on 2026-06-15 and ended on 2026-07-27 when CPS v6.8 went live. GTS stated that no certificates were affected and that issuance was not stopped because the certificates were technically valid under the existing CP/CPS prerequisites. In the latest update, GTS said it had completed internal procedural documentation changes so that a formal tracking ticket must be created for every requirement identified during a Root Program policy review. GTS also asked for the nextUpdate field to be set to 2026-10-15.

Model: gpt-5.4-mini Generated: 2026-08-04 07:21 UTC Revised: 2026-08-30 07:00 UTC Confidence: 0.98 3 comments
Chronology
  1. Chrome Root Program Section 1.1.3 took effect, creating the CP/CPS attestation requirement.
  2. An external inquiry identified the missing CP/CPS attestation.
  3. Google Trust Services mitigated the issue by publishing CPS v6.8.
  4. Google Trust Services said it had completed internal procedural documentation updates and requested a nextUpdate date.
Thread Activity
  1. Google representative — GTS opened a preliminary incident report saying its CP/CPS was missing the required Chrome Root Program and CCADB policy statement and that a full report would follow.
  2. Google representative — GTS filed the full incident report, stating the non-compliance period, the mitigation timeline, and that no certificates were affected.
  3. Google representative — GTS said it had updated internal procedures to require a formal tracking ticket for every Root Program requirement and requested that nextUpdate be set to 2026-10-15.
Participants
Google representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#2068900 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Policy Document Issue Opened 2026-09-03 Still Open · 74% similar
Firmaprofesional: CP/CPS missing Chrome Root Program and CCADB policy attestation
#2056934 ASSIGNED Ca Certificate Compliance Incident Externally Reported Incident Policy Document Issue Opened 2026-07-22 Still Open · 73% similar
Actalis: failure to timely update CP/CPS for AgID SubCAs
#2053948 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Ccadb Disclosure Issue Opened 2026-07-09 Still Open · 72% similar
IdenTrust: Delayed disclosure of Intermediate CA in CCADB
#2066649 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Problem Reporting Failure Opened 2026-08-26 Still Open · 70% similar
Microsoft PKI Services: Missed Seven-Day Update for Bugzilla 2059818
#2066809 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Policy Document Issue Opened 2026-08-26 Still Open · 70% similar
Microsec: Insufficent support for "unspecified (0)" revocation reason
#2057919 ASSIGNED Incident Problem Reporting Failure Revocation Issue Delayed Revocation Opened 2026-07-26 Still Open · 70% similar
SSL.com: Failure to respond to Certificate Problem Report within 24 hours
#2032468 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-04-16 · Closed 2026-08-09 · 70% similar
VISA: Misissuance detected by PKIMetal
#2066068 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Problem Reporting Failure Opened 2026-08-24 Still Open · 69% similar
SECOM: Missing Prior Notification and Approval for a Cross-Certificate Extending Trust to Externally-Operated JPRS CAs

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action