OneCRL Entry
3a6ab1f4-89cb-4987-b8b2-54797f88930b
Revocation Entry
- Status
- enabled
- Serial
0A923F1ADBAE485B2906EE04- Last Modified
- 2018-12-14 18:16:38 UTC
- Schema
- 1552491702967
Issuer
- DN
- C=BE, O=GlobalSign nv-sa, CN=GlobalSign Organization Validation CA - SHA256 - G2
- DN SHA-256
9e438628917ccd59955cb13fa1a04696ea2249c6dab29b5780a2e813957a9d53- Issuer DER
MGYxCzAJBgNVBAYTAkJFMRkwFwYDVQQKExBHbG9iYWxTaWduIG52LXNhMTwwOgYDVQQDEzNHbG9iYWxTaWduIE9yZ2FuaXphdGlvbiBWYWxpZGF0aW9uIENBIC0gU0hBMjU2IC0gRzI=
Context
- Bugzilla
- 1513609
- Action
- Added a compromised Alibaba *.alipcsec.com certificate to OneCRL; initiated by Wayne Thayer (w**********r@mozilla.com). The local OneCRL record was created on 2018-12-14T18:02:57Z and the bug thread says it was added to OneCRL on 2019-01-07 via bug 1514308.
- Confidence
- Explicit in OneCRL thread · 0.98
CCADB Link
- Issuer CA
- GlobalSign Organization Validation CA - SHA256 - G2
- CA Owner
- GlobalSign nv-sa
AI Summary
Generated 2026-06-30 11:05 UTC · Model: gpt-5.4-miniWayne Thayer opened Bugzilla 1513609 on 2018-12-12 to add a compromised Alibaba .alipcsec.com certificate to OneCRL. The thread states that the private key was reported embedded in Alibaba Youku Windows client software and that GlobalSign confirmed the compromise and revoked the certificate. A OneCRL entry was later added on 2019-01-07 via bug 1514308. The local OneCRL record shows the entry was enabled, with detail_who set to w*********r@mozilla.com, detail_why set to key compromise, and detail_created at 2018-12-14T18:02:57Z. The OneCRL item is for the GlobalSign Organization Validation CA - SHA256 - G2 issuer and serial 0A923F1ADBAE485B2906EE04. The CCADB trigger is not explicitly stated in the thread, but the timeline supports that the revocation was based on a revoked certificate due to key compromise.
Added a compromised Alibaba *.alipcsec.com certificate to OneCRL; initiated by Wayne Thayer (w**********r@mozilla.com). The local OneCRL record was created on 2018-12-14T18:02:57Z and the bug thread says it was added to OneCRL on 2019-01-07 via bug 1514308.
Unknown / not stated explicitly; timeline indicates key compromise and a revoked certificate, with local OneCRL detail_why='key compromise'.
Alibaba Youku Windows client software reportedly embedded the private key; GlobalSign confirmed the compromise and revoked the certificate.
Explicit in OneCRL thread · 0.98
- 2018-12-12Bug 1513609 opened to add a compromised Alibaba *.alipcsec.com certificate to OneCRL.
- 2018-12-12Wayne Thayer stated the private key was reported embedded in Alibaba Youku Windows client software and that GlobalSign confirmed the compromise and revoked the certificate.
- 2018-12-14Local OneCRL entry was created with detail_why='key compromise' and detail_who='w**********r@mozilla.com'.
- 2019-01-07Comment states the certificate was added to OneCRL via bug 1514308.
AI-generated from the OneCRL record and linked Bugzilla thread. Mozilla and CCADB records remain authoritative.
Raw Remote Settings Record
{
"schema": 1552491702967,
"details": {
"bug": "https://bugzilla.mozilla.org/show_bug.cgi?id=1513609",
"who": "wthayer@mozilla.com",
"why": "key compromise",
"name": "",
"created": "2018-12-14T18:02:57Z"
},
"enabled": true,
"issuerName": "MGYxCzAJBgNVBAYTAkJFMRkwFwYDVQQKExBHbG9iYWxTaWduIG52LXNhMTwwOgYDVQQDEzNHbG9iYWxTaWduIE9yZ2FuaXphdGlvbiBWYWxpZGF0aW9uIENBIC0gU0hBMjU2IC0gRzI=",
"serialNumber": "CpI/GtuuSFspBu4E",
"id": "3a6ab1f4-89cb-4987-b8b2-54797f88930b",
"last_modified": 1544811398633
}