← OneCRL Browser

OneCRL Entry

112fbc85-4e1a-4740-978d-a717fd02b1eb

Revocation Entry

Status
enabled
Serial
00A9911AC9CCB42F26721664ADF10F42FB
Last Modified
2019-08-21 04:14:52 UTC
Schema
1566360891850

Issuer

DN
C=US, ST=TX, L=Houston, O=cPanel, Inc., CN=cPanel, Inc. Certification Authority
DN SHA-256
b8ed905edcc18bf3a0c1dddfd7c6c68cea87c66bc2c48676bcda95a8a77618a3
Issuer DER
MHIxCzAJBgNVBAYTAlVTMQswCQYDVQQIEwJUWDEQMA4GA1UEBxMHSG91c3RvbjEVMBMGA1UEChMMY1BhbmVsLCBJbmMuMS0wKwYDVQQDEyRjUGFuZWwsIEluYy4gQ2VydGlmaWNhdGlvbiBBdXRob3JpdHk=

Context

Bugzilla
1572287
Action
Two cPanel, Inc. Certification Authority certificates were added to OneCRL by w**********r@mozilla.com on 2019-08-17, with last modification on 2019-08-21; the OneCRL detail_why field says 'registry compromise'.
Confidence
Explicit in OneCRL thread · 0.97

CCADB Link

Issuer CA
cPanel, Inc. Certification Authority
CA Owner
Sectigo

AI Summary

Generated 2026-06-30 11:01 UTC · Model: gpt-5.4-mini

Wayne Thayer opened the bug on 2019-08-08 to add attacker-controlled google.tg certificates to OneCRL, citing a misissued certificate report and a likely .tg ccTLD compromise. Sectigo later clarified that the certificate was not a CA misissuance, but was issued after normal domain-control validation with an empty CAA RRset. Robin Alden of Sectigo said on 2019-08-09 that the google.tg certificate had been revoked, and the Amazon security team later led to revocation of a related amazon.tg certificate. Wayne then stated on 2019-08-22 that both certificates were now in OneCRL. The OneCRL entries show two cPanel, Inc. Certification Authority certificates, both added by w**********r@mozilla.com on 2019-08-17 and last modified on 2019-08-21, with the reason recorded as registry compromise. The thread does not state a CCADB candidate-report state or a specific CCADB revocation field as the trigger; the qualification appears to be based on the reported registry compromise and the revocations. The external cause is explicitly tied to a .tg registry compromise discussed in the bug and linked Mozilla dev-security-policy thread.

OneCRL action

Two cPanel, Inc. Certification Authority certificates were added to OneCRL by w**********r@mozilla.com on 2019-08-17, with last modification on 2019-08-21; the OneCRL detail_why field says 'registry compromise'.

CCADB trigger

Unknown / not stated; the thread does not mention a CCADB candidate-report state or specific revocation field, only that the OneCRL entries were added for registry compromise after revocation.

External cause

Explicitly linked .tg registry compromise affecting attacker-controlled certificates; no CA closure is stated.

Confidence

Explicit in OneCRL thread · 0.97

Chronology
  • 2019-08-08Wayne Thayer filed Bug 1572287 to add attacker-controlled google.tg certificates to OneCRL.
  • 2019-08-09Sectigo said the google.tg certificate had been revoked; later the Amazon security team led to revocation of amazon.tg.
  • 2019-08-17Two cPanel CA certificates were created in OneCRL by w**********r@mozilla.com with reason 'registry compromise'.
  • 2019-08-21The OneCRL entries were last modified.
  • 2019-08-22Wayne Thayer stated that the two certificates were now in OneCRL.

AI-generated from the OneCRL record and linked Bugzilla thread. Mozilla and CCADB records remain authoritative.

Raw Remote Settings Record

{
    "schema": 1566360891850,
    "details": {
        "bug": "https://bugzilla.mozilla.org/show_bug.cgi?id=1572287",
        "who": "wthayer@mozilla.com",
        "why": "registry compromise",
        "name": "",
        "created": "2019-08-17T19:35:20Z"
    },
    "enabled": true,
    "issuerName": "MHIxCzAJBgNVBAYTAlVTMQswCQYDVQQIEwJUWDEQMA4GA1UEBxMHSG91c3RvbjEVMBMGA1UEChMMY1BhbmVsLCBJbmMuMS0wKwYDVQQDEyRjUGFuZWwsIEluYy4gQ2VydGlmaWNhdGlvbiBBdXRob3JpdHk=",
    "serialNumber": "AKmRGsnMtC8mchZkrfEPQvs=",
    "id": "112fbc85-4e1a-4740-978d-a717fd02b1eb",
    "last_modified": 1566360892211
}

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action