← OneCRL Browser

OneCRL Entry

68c90a6f-5401-44b7-b25d-e54377d96f7a

Revocation Entry

Status
disabled
Serial
75A8B9B5231B9F950AED62BAFB467147
Last Modified
2020-11-20 00:45:30 UTC
Schema
1605805268441

Issuer

DN
OU=GlobalSign Root CA - R3, O=GlobalSign, CN=GlobalSign
DN SHA-256
5bdab67a96c25c9b087f12e81ed40d23384becf64c4a37f50048191cc2427590
Issuer DER
MEwxIDAeBgNVBAsTF0dsb2JhbFNpZ24gUm9vdCBDQSAtIFIzMRMwEQYDVQQKEwpHbG9iYWxTaWduMRMwEQYDVQQDEwpHbG9iYWxTaWdu

Context

Bugzilla
1678378
Action
ccadb2onercl bot added OneCRL entries for revoked intermediate certificates; the local OneCRL records show the batch was last modified on 2020-11-20T00:45:29Z-00:45:30Z, with STAGE approval at 2020-11-20T00:43:07Z and PROD approval at 2020-11-20T00:45:41Z.
Confidence
Explicit in OneCRL thread · 0.98

CCADB Link

Issuer CA
GlobalSign
CA Owner
GlobalSign nv-sa

AI Summary

Generated 2026-06-30 11:41 UTC · Model: gpt-5.4-mini

This bug added a batch of OneCRL entries for revoked intermediate certificates reported in the CCADB. The additions were created by the ccadb2onercl bot and later confirmed by Kathleen Wilson as the correct entries to add. The thread states these revocations had happened a while earlier and had already been added to other root-store equivalents of OneCRL, so no TLS Canary run was needed. The OneCRL records show the entries were disabled and last modified on 2020-11-20T00:45:29Z to 2020-11-20T00:45:30Z. The bug was approved at STAGE at 2020-11-20T00:43:07Z and at PROD at 2020-11-20T00:45:41Z. The thread does not state the specific CCADB revocation fields or the external compliance incident/CA closure for these certificates.

OneCRL action

ccadb2onercl bot added OneCRL entries for revoked intermediate certificates; the local OneCRL records show the batch was last modified on 2020-11-20T00:45:29Z-00:45:30Z, with STAGE approval at 2020-11-20T00:43:07Z and PROD approval at 2020-11-20T00:45:41Z.

CCADB trigger

Explicitly stated only as revoked intermediate certificates reported in the CCADB; specific CCADB fields/candidate-report state not stated.

External cause

Unknown / not stated; the thread only says the revocations happened earlier and were already present in other root-store equivalents of OneCRL.

Confidence

Explicit in OneCRL thread · 0.98

Chronology
  • 2020-11-19ccadb2onercl bot created the bug and attached proposed OneCRL additions based on revoked intermediate certificates reported in the CCADB.
  • 2020-11-20Kathleen Wilson confirmed the entries were correct and said TLS Canary was unnecessary because the revocations were older and already in other root-store equivalents.
  • 2020-11-20The change was approved at STAGE.
  • 2020-11-20The change was approved at PROD.
  • 2021-04-15Bug was moved to Core::Security Block-lists, Allow-lists, and other State.

AI-generated from the OneCRL record and linked Bugzilla thread. Mozilla and CCADB records remain authoritative.

Raw Remote Settings Record

{
    "schema": 1605805268441,
    "details": {
        "bug": "https://bugzilla.mozilla.org/show_bug.cgi?id=1678378",
        "who": "",
        "why": "",
        "name": "",
        "created": ""
    },
    "enabled": false,
    "issuerName": "MEwxIDAeBgNVBAsTF0dsb2JhbFNpZ24gUm9vdCBDQSAtIFIzMRMwEQYDVQQKEwpHbG9iYWxTaWduMRMwEQYDVQQDEwpHbG9iYWxTaWdu",
    "serialNumber": "dai5tSMbn5UK7WK6+0ZxRw==",
    "id": "68c90a6f-5401-44b7-b25d-e54377d96f7a",
    "last_modified": 1605833130329
}

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action