← OneCRL Browser

OneCRL Entry

823b3acc-228f-43ce-a7b4-151cf75934d3

Revocation Entry

Status
disabled
Serial
6FA3CC76E393D62826D9BE57AD26CDD5AC91603D
Last Modified
2020-11-20 00:45:30 UTC
Schema
1605805280608

Issuer

DN
C=BM, O=QuoVadis Limited, CN=QuoVadis Root CA 2
DN SHA-256
f1502792df303efb232e64e5c472eff9804eeda35966f16a207cd4112b3d3b2f
Issuer DER
MEUxCzAJBgNVBAYTAkJNMRkwFwYDVQQKExBRdW9WYWRpcyBMaW1pdGVkMRswGQYDVQQDExJRdW9WYWRpcyBSb290IENBIDI=

Context

Bugzilla
1678378
Action
ccadb2onercl bot added OneCRL entries for revoked intermediate certificates; the local OneCRL records show the batch was last modified on 2020-11-20T00:45:29Z-00:45:30Z, with STAGE approval at 2020-11-20T00:43:07Z and PROD approval at 2020-11-20T00:45:41Z.
Confidence
Explicit in OneCRL thread · 0.98

CCADB Link

Issuer CA
QuoVadis Root CA 2
CA Owner
DigiCert

AI Summary

Generated 2026-06-30 11:41 UTC · Model: gpt-5.4-mini

This bug added a batch of OneCRL entries for revoked intermediate certificates reported in the CCADB. The additions were created by the ccadb2onercl bot and later confirmed by Kathleen Wilson as the correct entries to add. The thread states these revocations had happened a while earlier and had already been added to other root-store equivalents of OneCRL, so no TLS Canary run was needed. The OneCRL records show the entries were disabled and last modified on 2020-11-20T00:45:29Z to 2020-11-20T00:45:30Z. The bug was approved at STAGE at 2020-11-20T00:43:07Z and at PROD at 2020-11-20T00:45:41Z. The thread does not state the specific CCADB revocation fields or the external compliance incident/CA closure for these certificates.

OneCRL action

ccadb2onercl bot added OneCRL entries for revoked intermediate certificates; the local OneCRL records show the batch was last modified on 2020-11-20T00:45:29Z-00:45:30Z, with STAGE approval at 2020-11-20T00:43:07Z and PROD approval at 2020-11-20T00:45:41Z.

CCADB trigger

Explicitly stated only as revoked intermediate certificates reported in the CCADB; specific CCADB fields/candidate-report state not stated.

External cause

Unknown / not stated; the thread only says the revocations happened earlier and were already present in other root-store equivalents of OneCRL.

Confidence

Explicit in OneCRL thread · 0.98

Chronology
  • 2020-11-19ccadb2onercl bot created the bug and attached proposed OneCRL additions based on revoked intermediate certificates reported in the CCADB.
  • 2020-11-20Kathleen Wilson confirmed the entries were correct and said TLS Canary was unnecessary because the revocations were older and already in other root-store equivalents.
  • 2020-11-20The change was approved at STAGE.
  • 2020-11-20The change was approved at PROD.
  • 2021-04-15Bug was moved to Core::Security Block-lists, Allow-lists, and other State.

AI-generated from the OneCRL record and linked Bugzilla thread. Mozilla and CCADB records remain authoritative.

Raw Remote Settings Record

{
    "schema": 1605805280608,
    "details": {
        "bug": "https://bugzilla.mozilla.org/show_bug.cgi?id=1678378",
        "who": "",
        "why": "",
        "name": "",
        "created": ""
    },
    "enabled": false,
    "issuerName": "MEUxCzAJBgNVBAYTAkJNMRkwFwYDVQQKExBRdW9WYWRpcyBMaW1pdGVkMRswGQYDVQQDExJRdW9WYWRpcyBSb290IENBIDI=",
    "serialNumber": "b6PMduOT1igm2b5XrSbN1ayRYD0=",
    "id": "823b3acc-228f-43ce-a7b4-151cf75934d3",
    "last_modified": 1605833130114
}

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action