← OneCRL Browser

OneCRL Entry

3a6ab1f4-89cb-4987-b8b2-54797f88930b

Revocation Entry

Status
enabled
Serial
0A923F1ADBAE485B2906EE04
Last Modified
2018-12-14 18:16:38 UTC
Schema
1552491702967

Issuer

DN
C=BE, O=GlobalSign nv-sa, CN=GlobalSign Organization Validation CA - SHA256 - G2
DN SHA-256
9e438628917ccd59955cb13fa1a04696ea2249c6dab29b5780a2e813957a9d53
Issuer DER
MGYxCzAJBgNVBAYTAkJFMRkwFwYDVQQKExBHbG9iYWxTaWduIG52LXNhMTwwOgYDVQQDEzNHbG9iYWxTaWduIE9yZ2FuaXphdGlvbiBWYWxpZGF0aW9uIENBIC0gU0hBMjU2IC0gRzI=

Context

Bugzilla
1513609
Action
Added a compromised Alibaba *.alipcsec.com certificate to OneCRL; initiated by Wayne Thayer (w**********r@mozilla.com). The local OneCRL record was created on 2018-12-14T18:02:57Z and the bug thread says it was added to OneCRL on 2019-01-07 via bug 1514308.
Confidence
Explicit in OneCRL thread · 0.98

AI Summary

Generated 2026-06-30 11:05 UTC · Model: gpt-5.4-mini

Wayne Thayer opened Bugzilla 1513609 on 2018-12-12 to add a compromised Alibaba .alipcsec.com certificate to OneCRL. The thread states that the private key was reported embedded in Alibaba Youku Windows client software and that GlobalSign confirmed the compromise and revoked the certificate. A OneCRL entry was later added on 2019-01-07 via bug 1514308. The local OneCRL record shows the entry was enabled, with detail_who set to w*********r@mozilla.com, detail_why set to key compromise, and detail_created at 2018-12-14T18:02:57Z. The OneCRL item is for the GlobalSign Organization Validation CA - SHA256 - G2 issuer and serial 0A923F1ADBAE485B2906EE04. The CCADB trigger is not explicitly stated in the thread, but the timeline supports that the revocation was based on a revoked certificate due to key compromise.

OneCRL action

Added a compromised Alibaba *.alipcsec.com certificate to OneCRL; initiated by Wayne Thayer (w**********r@mozilla.com). The local OneCRL record was created on 2018-12-14T18:02:57Z and the bug thread says it was added to OneCRL on 2019-01-07 via bug 1514308.

CCADB trigger

Unknown / not stated explicitly; timeline indicates key compromise and a revoked certificate, with local OneCRL detail_why='key compromise'.

External cause

Alibaba Youku Windows client software reportedly embedded the private key; GlobalSign confirmed the compromise and revoked the certificate.

Confidence

Explicit in OneCRL thread · 0.98

Chronology
  • 2018-12-12Bug 1513609 opened to add a compromised Alibaba *.alipcsec.com certificate to OneCRL.
  • 2018-12-12Wayne Thayer stated the private key was reported embedded in Alibaba Youku Windows client software and that GlobalSign confirmed the compromise and revoked the certificate.
  • 2018-12-14Local OneCRL entry was created with detail_why='key compromise' and detail_who='w**********r@mozilla.com'.
  • 2019-01-07Comment states the certificate was added to OneCRL via bug 1514308.

AI-generated from the OneCRL record and linked Bugzilla thread. Mozilla and CCADB records remain authoritative.

Raw Remote Settings Record

{
    "schema": 1552491702967,
    "details": {
        "bug": "https://bugzilla.mozilla.org/show_bug.cgi?id=1513609",
        "who": "wthayer@mozilla.com",
        "why": "key compromise",
        "name": "",
        "created": "2018-12-14T18:02:57Z"
    },
    "enabled": true,
    "issuerName": "MGYxCzAJBgNVBAYTAkJFMRkwFwYDVQQKExBHbG9iYWxTaWduIG52LXNhMTwwOgYDVQQDEzNHbG9iYWxTaWduIE9yZ2FuaXphdGlvbiBWYWxpZGF0aW9uIENBIC0gU0hBMjU2IC0gRzI=",
    "serialNumber": "CpI/GtuuSFspBu4E",
    "id": "3a6ab1f4-89cb-4987-b8b2-54797f88930b",
    "last_modified": 1544811398633
}

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action