Symantec erroneous SHA-1 certificates
24ccf065-b88b-0fc9-1d1f-6c7722ca4faa
Revocation Entry
- Status
- enabled
- Serial
514155DD2D9C52274E3AFEC448DEB936- Last Modified
- 2016-11-28 16:06:01 UTC
- Schema
- 1552493036467
Issuer
- DN
- C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)10, CN=VeriSign Class 3 International Server CA - G3
- DN SHA-256
0ca28e71d04c14a9d6b4dbc8cbf6ed4c205925e4829d0ca030f6863944deab40- Issuer DER
MIG8MQswCQYDVQQGEwJVUzEXMBUGA1UEChMOVmVyaVNpZ24sIEluYy4xHzAdBgNVBAsTFlZlcmlTaWduIFRydXN0IE5ldHdvcmsxOzA5BgNVBAsTMlRlcm1zIG9mIHVzZSBhdCBodHRwczovL3d3dy52ZXJpc2lnbi5jb20vcnBhIChjKTEwMTYwNAYDVQQDEy1WZXJpU2lnbiBDbGFzcyAzIEludGVybmF0aW9uYWwgU2VydmVyIENBIC0gRzM=
Context
- Bugzilla
- 1286752
- Action
- Eight OneCRL blocklist entries were added for the issuer VeriSign Class 3 International Server CA - G3, initiated by Mark Goodwin (:mgoodwin) on 2016-07-14 and processed by Andrew Williamson (:eviljeff) with confirmation by Jason Thomas.
- Confidence
- Explicit in OneCRL thread · 0.98
CCADB Link
- Issuer CA
- VeriSign Class 3 International Server CA - G3
- CA Owner
- DigiCert
AI Summary
Generated 2026-06-30 11:47 UTC · Model: gpt-5.4-miniMozilla added eight OneCRL blocklist entries for Symantec erroneously produced and issued SHA-1 certificates. The entries all use the same issuer, VeriSign Class 3 International Server CA - G3, and were added as serial/issuer pairs. The action was initiated by Mark Goodwin (:mgoodwin) in Bugzilla, who cited the dev-security-policy mailing list thread and posted the serials on 2016-07-14. Andrew Williamson (:eviljeff) then created the certificate list attachment and requested processing, and Jason Thomas confirmed it was done. The OneCRL records show the entries were created on 2016-07-14 and last modified on 2016-11-28, but the thread does not state a CCADB revocation field or candidate-report state. The external cause is explicit in the bug title and linked thread: Symantec had erroneously produced and issued the SHA-1 certificates.
Eight OneCRL blocklist entries were added for the issuer VeriSign Class 3 International Server CA - G3, initiated by Mark Goodwin (:mgoodwin) on 2016-07-14 and processed by Andrew Williamson (:eviljeff) with confirmation by Jason Thomas.
Unknown / not stated; the thread does not mention a CCADB revocation field, candidate report, or manual-add qualification beyond the blocklist request itself.
Symantec erroneously produced and issued SHA-1 certificates, as stated in the Bugzilla summary and linked dev-security-policy thread.
Explicit in OneCRL thread · 0.98
- 2016-07-14Mark Goodwin opened Bugzilla 1286752 to add blocklist entries for eight Symantec erroneous SHA-1 certificates.
- 2016-07-14Andrew Williamson created an attachment listing the certs as serial/issuer pairs and asked Jason to run the processing script.
- 2016-07-14Jason Thomas replied 'Done.'
- 2016-11-28The OneCRL entries show last_modified_at timestamps on this date.
AI-generated from the OneCRL record and linked Bugzilla thread. Mozilla and CCADB records remain authoritative.
Raw Remote Settings Record
{
"schema": 1552493036467,
"details": {
"bug": "https://bugzilla.mozilla.org/show_bug.cgi?id=1286752",
"who": ".",
"why": ".",
"name": "Symantec erroneous SHA-1 certificates",
"created": "2016-07-14T14:40:23Z"
},
"enabled": true,
"issuerName": "MIG8MQswCQYDVQQGEwJVUzEXMBUGA1UEChMOVmVyaVNpZ24sIEluYy4xHzAdBgNVBAsTFlZlcmlTaWduIFRydXN0IE5ldHdvcmsxOzA5BgNVBAsTMlRlcm1zIG9mIHVzZSBhdCBodHRwczovL3d3dy52ZXJpc2lnbi5jb20vcnBhIChjKTEwMTYwNAYDVQQDEy1WZXJpU2lnbiBDbGFzcyAzIEludGVybmF0aW9uYWwgU2VydmVyIENBIC0gRzM=",
"serialNumber": "UUFV3S2cUidOOv7ESN65Ng==",
"id": "24ccf065-b88b-0fc9-1d1f-6c7722ca4faa",
"last_modified": 1480349161103
}