OneCRL Entry
6f25596b-57e5-4b88-9db2-ee03c5fd22fa
Revocation Entry
- Status
- disabled
- Serial
751E3F3DE96CD728B26662C55232587B- Last Modified
- 2021-04-09 22:35:40 UTC
- Schema
- 1617814860968
Issuer
- DN
- OU=GlobalSign Root CA - R3, O=GlobalSign, CN=GlobalSign
- DN SHA-256
5bdab67a96c25c9b087f12e81ed40d23384becf64c4a37f50048191cc2427590- Issuer DER
MEwxIDAeBgNVBAsTF0dsb2JhbFNpZ24gUm9vdCBDQSAtIFIzMRMwEQYDVQQKEwpHbG9iYWxTaWduMRMwEQYDVQQDEwpHbG9iYWxTaWdu
Context
- Bugzilla
- 1703616
- Action
- A batch of issuer/serial revocation entries for multiple revoked intermediate certificates was proposed for addition to OneCRL by the Common CA Database to OneCRL Bot on 2021-04-07T17:00:50Z, confirmed by Kathleen Wilson on 2021-04-08, approved in Kinto staging and then production by Dana Keeler on 2021-04-08 and 2021-04-09, and confirmed present in Firefox profiles on 2021-04-10.
- Confidence
- Explicit in OneCRL thread · 0.98
CCADB Link
- Issuer CA
- GlobalSign
- CA Owner
- GlobalSign nv-sa
AI Summary
Generated 2026-06-30 11:41 UTC · Model: gpt-5.4This Bugzilla case tracks a batch addition of revoked intermediate certificate entries to Mozilla OneCRL. The bug was created automatically by the Common CA Database to OneCRL Bot on 2021-04-07, and the opening comment states the entries were being added based on revoked intermediate certificates reported in the CCADB. Kathleen Wilson explicitly confirmed on 2021-04-08 that the listed entries were the correct ones to add to OneCRL and said TLS Canary was not needed for this set of changes. Dana Keeler then approved the changes in staging, later confirmed staging looked correct, ran the onecrl-entry-checker tool at Kathleen's request, and approved the changes for production on 2021-04-09. Kathleen confirmed on 2021-04-10 that the new OneCRL entries were present in her Nightly and Release Firefox profiles. The local OneCRL entry list tied to this bug contains multiple issuer/serial revocation entries across several CA owners, including SECOM Trust Systems, GlobalSign, DigiCert/Baltimore, and Chunghwa Telecom. The thread does not state per-certificate revocation reasons, revocation dates, or any external compliance incident or CA closure explaining why those intermediates had been revoked. Any more specific trigger beyond revoked intermediate status in CCADB would be inference rather than explicit fact from this thread.
A batch of issuer/serial revocation entries for multiple revoked intermediate certificates was proposed for addition to OneCRL by the Common CA Database to OneCRL Bot on 2021-04-07T17:00:50Z, confirmed by Kathleen Wilson on 2021-04-08, approved in Kinto staging and then production by Dana Keeler on 2021-04-08 and 2021-04-09, and confirmed present in Firefox profiles on 2021-04-10.
Explicitly stated as revoked intermediate certificates reported in the CCADB; no per-entry revocation reason, revocation date, candidate-report state, or manual-addition rationale is stated in the thread.
Unknown; the thread does not cite any related compliance incident, root program report, mailing list discussion, or CA closure as the reason these intermediates were revoked.
Explicit in OneCRL thread · 0.98
- 2021-04-07Bug 1703616 was created by the Common CA Database to OneCRL Bot.
- 2021-04-07Bot stated entries were being added to OneCRL based on revoked intermediate certificates reported in the CCADB.
- 2021-04-07Bot attached issuer/serial pairs, proposed OneCRL additions, and decoded entry details.
- 2021-04-08Bot posted that the changes were still in review.
- 2021-04-08Kathleen Wilson confirmed the entries were correct and said TLS Canary was not needed.
- 2021-04-08Dana Keeler approved the changes in staging.
- 2021-04-09Bot again posted that the changes were still in review.
- 2021-04-09Dana Keeler said staging looked correct.
- 2021-04-09Kathleen Wilson requested onecrl-entry-checker output.
- 2021-04-09Dana Keeler attached onecrl-entry-checker output.
- 2021-04-09Kathleen Wilson said the output looked correct and requested production approval.
- 2021-04-09Dana Keeler approved the changes for production.
- 2021-04-10Kathleen Wilson confirmed the new OneCRL entries were present in her Nightly and Release Firefox profiles.
- 2021-04-15Automation moved the bug to Core::Security Block-lists, Allow-lists, and other State.
AI-generated from the OneCRL record and linked Bugzilla thread. Mozilla and CCADB records remain authoritative.
Raw Remote Settings Record
{
"schema": 1617814860968,
"details": {
"bug": "https://bugzilla.mozilla.org/show_bug.cgi?id=1703616",
"who": "",
"why": "",
"name": "",
"created": ""
},
"enabled": false,
"issuerName": "MEwxIDAeBgNVBAsTF0dsb2JhbFNpZ24gUm9vdCBDQSAtIFIzMRMwEQYDVQQKEwpHbG9iYWxTaWduMRMwEQYDVQQDEwpHbG9iYWxTaWdu",
"serialNumber": "dR4/Pels1yiyZmLFUjJYew==",
"id": "6f25596b-57e5-4b88-9db2-ee03c5fd22fa",
"last_modified": 1618007740379
}