OneCRL Entry
4af94082-5a8b-44f4-8522-3fad8de6dac0
Revocation Entry
- Status
- disabled
- Serial
22B9B13AF2D9E4F386- Last Modified
- 2021-04-09 22:35:40 UTC
- Schema
- 1617814862463
Issuer
- DN
- C=JP, O=SECOM Trust Systems CO.,LTD., OU=Security Communication RootCA2
- DN SHA-256
42a64d1b796fbf88b987504ad560eaa1e46777712ae4042ba8f8713d831f6849- Issuer DER
MF0xCzAJBgNVBAYTAkpQMSUwIwYDVQQKExxTRUNPTSBUcnVzdCBTeXN0ZW1zIENPLixMVEQuMScwJQYDVQQLEx5TZWN1cml0eSBDb21tdW5pY2F0aW9uIFJvb3RDQTI=
Context
- Bugzilla
- 1703616
- Action
- A batch of issuer/serial revocation entries for multiple revoked intermediate certificates was proposed for addition to OneCRL by the Common CA Database to OneCRL Bot on 2021-04-07T17:00:50Z, confirmed by Kathleen Wilson on 2021-04-08, approved in Kinto staging and then production by Dana Keeler on 2021-04-08 and 2021-04-09, and confirmed present in Firefox profiles on 2021-04-10.
- Confidence
- Explicit in OneCRL thread · 0.98
CCADB Link
- Issuer CA
- Security Communication RootCA2
- CA Owner
- SECOM Trust Systems CO., LTD.
AI Summary
Generated 2026-06-30 11:41 UTC · Model: gpt-5.4This Bugzilla case tracks a batch addition of revoked intermediate certificate entries to Mozilla OneCRL. The bug was created automatically by the Common CA Database to OneCRL Bot on 2021-04-07, and the opening comment states the entries were being added based on revoked intermediate certificates reported in the CCADB. Kathleen Wilson explicitly confirmed on 2021-04-08 that the listed entries were the correct ones to add to OneCRL and said TLS Canary was not needed for this set of changes. Dana Keeler then approved the changes in staging, later confirmed staging looked correct, ran the onecrl-entry-checker tool at Kathleen's request, and approved the changes for production on 2021-04-09. Kathleen confirmed on 2021-04-10 that the new OneCRL entries were present in her Nightly and Release Firefox profiles. The local OneCRL entry list tied to this bug contains multiple issuer/serial revocation entries across several CA owners, including SECOM Trust Systems, GlobalSign, DigiCert/Baltimore, and Chunghwa Telecom. The thread does not state per-certificate revocation reasons, revocation dates, or any external compliance incident or CA closure explaining why those intermediates had been revoked. Any more specific trigger beyond revoked intermediate status in CCADB would be inference rather than explicit fact from this thread.
A batch of issuer/serial revocation entries for multiple revoked intermediate certificates was proposed for addition to OneCRL by the Common CA Database to OneCRL Bot on 2021-04-07T17:00:50Z, confirmed by Kathleen Wilson on 2021-04-08, approved in Kinto staging and then production by Dana Keeler on 2021-04-08 and 2021-04-09, and confirmed present in Firefox profiles on 2021-04-10.
Explicitly stated as revoked intermediate certificates reported in the CCADB; no per-entry revocation reason, revocation date, candidate-report state, or manual-addition rationale is stated in the thread.
Unknown; the thread does not cite any related compliance incident, root program report, mailing list discussion, or CA closure as the reason these intermediates were revoked.
Explicit in OneCRL thread · 0.98
- 2021-04-07Bug 1703616 was created by the Common CA Database to OneCRL Bot.
- 2021-04-07Bot stated entries were being added to OneCRL based on revoked intermediate certificates reported in the CCADB.
- 2021-04-07Bot attached issuer/serial pairs, proposed OneCRL additions, and decoded entry details.
- 2021-04-08Bot posted that the changes were still in review.
- 2021-04-08Kathleen Wilson confirmed the entries were correct and said TLS Canary was not needed.
- 2021-04-08Dana Keeler approved the changes in staging.
- 2021-04-09Bot again posted that the changes were still in review.
- 2021-04-09Dana Keeler said staging looked correct.
- 2021-04-09Kathleen Wilson requested onecrl-entry-checker output.
- 2021-04-09Dana Keeler attached onecrl-entry-checker output.
- 2021-04-09Kathleen Wilson said the output looked correct and requested production approval.
- 2021-04-09Dana Keeler approved the changes for production.
- 2021-04-10Kathleen Wilson confirmed the new OneCRL entries were present in her Nightly and Release Firefox profiles.
- 2021-04-15Automation moved the bug to Core::Security Block-lists, Allow-lists, and other State.
AI-generated from the OneCRL record and linked Bugzilla thread. Mozilla and CCADB records remain authoritative.
Raw Remote Settings Record
{
"schema": 1617814862463,
"details": {
"bug": "https://bugzilla.mozilla.org/show_bug.cgi?id=1703616",
"who": "",
"why": "",
"name": "",
"created": ""
},
"enabled": false,
"issuerName": "MF0xCzAJBgNVBAYTAkpQMSUwIwYDVQQKExxTRUNPTSBUcnVzdCBTeXN0ZW1zIENPLixMVEQuMScwJQYDVQQLEx5TZWN1cml0eSBDb21tdW5pY2F0aW9uIFJvb3RDQTI=",
"serialNumber": "IrmxOvLZ5POG",
"id": "4af94082-5a8b-44f4-8522-3fad8de6dac0",
"last_modified": 1618007740352
}