unauthorized google.lk certificate
07b35e26-7e9f-490d-a90f-fa6847466994
Revocation Entry
- Status
- enabled
- Serial
N/A- Last Modified
- 2021-02-07 02:29:44 UTC
- Schema
- 1612554105658
Issuer
- DN
- N/A
- DN SHA-256
N/A- Issuer DER
Context
- Bugzilla
- 1691227
- Action
- Added a OneCRL entry for the unauthorized google.lk certificate (crt.sh id 4037732415) by Dana Keeler in Kinto Staging on 2021-02-07T00:34:14Z, reviewed/approved by Kathleen Wilson in staging and approved in Kinto Production at 2021-02-07T02:30:10Z; the entry was verified in Firefox on 2021-02-07T18:19:46Z.
- Confidence
- Explicit in OneCRL thread · 0.98
CCADB Link
- Issuer CA
- —
- CA Owner
- —
AI Summary
Generated 2026-06-30 10:43 UTC · Model: gpt-5.4-miniA single OneCRL entry was added for an unauthorized google.lk certificate, identified by crt.sh id 4037732415 and described as an unauthorized issuance. The request was initiated by Kathleen Wilson after receiving Google’s email notice about the issue and asking Mozilla to add the certificate to OneCRL. Dana Keeler added the entry to Kinto Staging, and Kathleen Wilson reviewed and approved it in staging before approving it in Kinto Production. The OneCRL detail records show the entry name, who, why, and created timestamp, and the published record was later verified in Firefox. The thread explicitly states Google had notified Sectigo and other browser vendors, but it does not state a CCADB revocation field or candidate-report state as the qualification trigger. The external cause is the unauthorized certificate issuance for google.lk by the Sri Lankan ccTLD registry, which was later made public by a notice on nic.lk.
Added a OneCRL entry for the unauthorized google.lk certificate (crt.sh id 4037732415) by Dana Keeler in Kinto Staging on 2021-02-07T00:34:14Z, reviewed/approved by Kathleen Wilson in staging and approved in Kinto Production at 2021-02-07T02:30:10Z; the entry was verified in Firefox on 2021-02-07T18:19:46Z.
Unknown / not stated; the thread only says Google reported the certificate as not authorized and that Google had revoked it by SHA-256(SPKI).
Unauthorized issuance of a google.lk certificate tied to the Sri Lankan ccTLD registry (nic.lk); Google notified Sectigo and browser vendors, and nic.lk later published a public notice.
Explicit in OneCRL thread · 0.98
- 2021-02-06Kathleen Wilson opened Bug 1691227 requesting OneCRL addition of the unauthorized google.lk certificate.
- 2021-02-07Kathleen Wilson noted Google had revoked the certificate by SHA-256(SPKI) and that Mozilla should do the same.
- 2021-02-07Dana Keeler added the entry to Kinto Staging and Kathleen Wilson reviewed/approved it in staging.
- 2021-02-07Dana Keeler confirmed staging publication and readiness for production review.
- 2021-02-07Kathleen Wilson approved the entry in Kinto Production.
- 2021-02-07Kathleen Wilson verified the entry in her Firefox profile.
- 2021-02-08Kathleen Wilson noted the registry published a public notice on nic.lk.
AI-generated from the OneCRL record and linked Bugzilla thread. Mozilla and CCADB records remain authoritative.
Raw Remote Settings Record
{
"schema": 1612554105658,
"details": {
"bug": "https://bugzilla.mozilla.org/show_bug.cgi?id=1691227",
"who": "dkeeler@mozilla.com",
"why": "unauthorized issuance",
"name": "unauthorized google.lk certificate",
"created": "2021-02-07T00:09:20Z"
},
"enabled": true,
"subject": "MBQxEjAQBgNVBAMTCWdvb2dsZS5saw==",
"pubKeyHash": "FeeuQMxLP3Iipab+Pn3Ef25G7poiUYOdspbWKtoqDfc=",
"id": "07b35e26-7e9f-490d-a90f-fa6847466994",
"last_modified": 1612664984721
}