← OneCRL Browser

OneCRL Entry

2fe0159b-6ae2-4f7b-a92b-63c27e5056fa

Revocation Entry

Status
disabled
Serial
7E0AF783E31368DD74160420E2C6EA70
Last Modified
2024-03-11 20:41:35 UTC
Schema
1709917272733

Issuer

DN
C=US, O=IdenTrust, CN=IdenTrust Commercial Root CA 1
DN SHA-256
6ad0b433aadfa4ee9810183dcae12b95f4a0b49e0c2a65d091aabd207342a852
Issuer DER
MEoxCzAJBgNVBAYTAlVTMRIwEAYDVQQKEwlJZGVuVHJ1c3QxJzAlBgNVBAMTHklkZW5UcnVzdCBDb21tZXJjaWFsIFJvb3QgQ0EgMQ==

Context

Bugzilla
1884400
Action
Five disabled OneCRL entries, identified by issuer DN and serial number, were proposed by the Common CA Database to OneCRL Bot on 2024-03-08, reviewed by Mozilla staff, approved in Kinto Production by John Schanck on 2024-03-11, and confirmed visible in Firefox Nightly and Beta on 2024-03-12.
Confidence
Explicit in OneCRL thread · 0.98

AI Summary

Generated 2026-06-30 11:41 UTC · Model: gpt-5.4

Bug 1884400 tracked the addition of five certificate issuer/serial entries to Mozilla OneCRL. The bug was created automatically on 2024-03-08 by the Common CA Database to OneCRL Bot, which stated that the entries were being added based on revoked intermediate certificates reported in the CCADB. The proposed entries covered two serials under vTrus ECC Root CA, two serials under vTrus Root CA, and one serial under IdenTrust Commercial Root CA 1. Ben Wilson confirmed on 2024-03-09 that these were the correct entries to add and said TLS Canary was not needed for this batch. John Schanck later verified staging/preview state and listed the five pending production additions, and Ben Wilson approved production on 2024-03-11. John Schanck then approved the changes in production, and Ben Wilson confirmed on 2024-03-12 that the changes appeared in Nightly and Beta Firefox profiles and at crt.sh's Mozilla OneCRL view. The thread does not state the individual CCADB revocation reasons or dates for the five certificates. The thread also does not explicitly identify any external compliance incident or CA closure as the cause of these revocations.

OneCRL action

Five disabled OneCRL entries, identified by issuer DN and serial number, were proposed by the Common CA Database to OneCRL Bot on 2024-03-08, reviewed by Mozilla staff, approved in Kinto Production by John Schanck on 2024-03-11, and confirmed visible in Firefox Nightly and Beta on 2024-03-12.

CCADB trigger

Explicitly stated as additions based on revoked intermediate certificates reported in the CCADB; no specific revocation reason, revocation date, or candidate-report field state is given in the thread.

External cause

unknown

Confidence

Explicit in OneCRL thread · 0.98

Chronology
  • 2024-03-08CCADB to OneCRL Bot opened Bug 1884400 and said entries were being added based on revoked intermediate certificates reported in the CCADB.
  • 2024-03-08Bot attached issuer/serial pairs, proposed OneCRL additions, and decoded entry details.
  • 2024-03-09Ben Wilson confirmed these were the correct entries to add and said TLS Canary was not needed.
  • 2024-03-10John Schanck posted staging/preview verification output showing five changes waiting in production.
  • 2024-03-11Ben Wilson approved proceeding with Kinto Production approval.
  • 2024-03-11John Schanck stated that the changes were approved in production.
  • 2024-03-12Ben Wilson confirmed the changes appeared in Nightly and Beta Firefox profiles and at crt.sh/mozilla-onecrl.

AI-generated from the OneCRL record and linked Bugzilla thread. Mozilla and CCADB records remain authoritative.

Raw Remote Settings Record

{
    "schema": 1709917272733,
    "details": {
        "bug": "https://bugzilla.mozilla.org/show_bug.cgi?id=1884400",
        "who": "",
        "why": "",
        "name": "",
        "created": ""
    },
    "enabled": false,
    "issuerName": "MEoxCzAJBgNVBAYTAlVTMRIwEAYDVQQKEwlJZGVuVHJ1c3QxJzAlBgNVBAMTHklkZW5UcnVzdCBDb21tZXJjaWFsIFJvb3QgQ0EgMQ==",
    "serialNumber": "fgr3g+MTaN10FgQg4sbqcA==",
    "id": "2fe0159b-6ae2-4f7b-a92b-63c27e5056fa",
    "last_modified": 1710189695287
}

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action