OneCRL Entry
3bf88a76-7257-48f4-8fea-76565915fa17
Revocation Entry
- Status
- disabled
- Serial
067F945755F187A91F8163F3E624620177FF38- Last Modified
- 2023-06-23 21:24:36 UTC
- Schema
- 1687366865737
Issuer
- DN
- C=US, O=Amazon, CN=Amazon Root CA 2
- DN SHA-256
723eb5ce2927402e5971f67ee7b266ebc06e3a0b057153873197eca685d75c4b- Issuer DER
MDkxCzAJBgNVBAYTAlVTMQ8wDQYDVQQKEwZBbWF6b24xGTAXBgNVBAMTEEFtYXpvbiBSb290IENBIDI=
Context
- Bugzilla
- 1839689
- Action
- Multiple issuer/serial entries were proposed for addition to OneCRL by the Common CA Database to OneCRL Bot on 2023-06-21, reviewed and confirmed by Kathleen Wilson, and approved in Kinto Production by Dana Keeler on 2023-06-23; the associated public OneCRL entry records show last_modified_at 2023-06-23T21:24:36Z.
- Confidence
- Explicit in OneCRL thread · 0.97
CCADB Link
- Issuer CA
- Amazon Root CA 2
- CA Owner
- Amazon Trust Services
AI Summary
Generated 2026-06-30 11:13 UTC · Model: gpt-5.4Bug 1839689 is a Mozilla OneCRL case created by the Common CA Database to OneCRL Bot on 2023-06-21. The bug states that entries were being added to OneCRL based on revoked intermediate certificates reported in the CCADB. The public OneCRL entry page data tied to this bug lists multiple issuer-and-serial entries, all later shown with enabled=false and last_modified_at 2023-06-23T21:24:36Z, consistent with production approval timing. Kathleen Wilson explicitly confirmed that these were the correct entries to add to OneCRL and said TLS Canary was not needed for this batch. Dana Keeler then performed staging checks, attached comparison outputs, and explicitly approved the changes in production on 2023-06-23. The thread does not identify per-certificate revocation reasons, revocation dates, or specific CCADB field values beyond saying the source was revoked intermediate certificates reported in the CCADB. The thread also does not cite any external compliance incident, CA closure, or related Bugzilla incident as the reason these certificates had been revoked. Based on the timeline, the listed OneCRL records were added through the standard bot-generated CCADB-to-OneCRL workflow and later verified in Firefox Nightly and Release profiles.
Multiple issuer/serial entries were proposed for addition to OneCRL by the Common CA Database to OneCRL Bot on 2023-06-21, reviewed and confirmed by Kathleen Wilson, and approved in Kinto Production by Dana Keeler on 2023-06-23; the associated public OneCRL entry records show last_modified_at 2023-06-23T21:24:36Z.
Explicitly stated as revoked intermediate certificates reported in the CCADB; no specific revocation reason, revocation date, candidate-report field state, or manual-addition rationale is stated for individual entries.
unknown
Explicit in OneCRL thread · 0.97
- 2023-06-21Bug 1839689 was created by the CCADB to OneCRL Bot.
- 2023-06-21Bot stated it was adding entries to OneCRL based on revoked intermediate certificates reported in the CCADB.
- 2023-06-21Bot attached issuer/serial pairs, proposed additions, and decoded entry details.
- 2023-06-21Kathleen Wilson confirmed these were the correct entries to add and said TLS Canary was not needed.
- 2023-06-22Bot posted that changes were still in review.
- 2023-06-23Dana Keeler attached compare.py outputs for review/validation.
- 2023-06-23Kathleen Wilson said the changes looked correct and asked for Kinto Production approval.
- 2023-06-23Dana Keeler approved the changes in production.
- 2023-06-23Kathleen Wilson verified the changes in Firefox Nightly and Release profiles.
AI-generated from the OneCRL record and linked Bugzilla thread. Mozilla and CCADB records remain authoritative.
Raw Remote Settings Record
{
"schema": 1687366865737,
"details": {
"bug": "https://bugzilla.mozilla.org/show_bug.cgi?id=1839689",
"who": "",
"why": "",
"name": "",
"created": ""
},
"enabled": false,
"issuerName": "MDkxCzAJBgNVBAYTAlVTMQ8wDQYDVQQKEwZBbWF6b24xGTAXBgNVBAMTEEFtYXpvbiBSb290IENBIDI=",
"serialNumber": "Bn+UV1Xxh6kfgWPz5iRiAXf/OA==",
"id": "3bf88a76-7257-48f4-8fea-76565915fa17",
"last_modified": 1687555476893
}