OneCRL Entry
8ca0cf31-3b80-4751-a021-08f346882481
Revocation Entry
- Status
- disabled
- Serial
1D6A0A7890840919BEB89EEBC49AA288- Last Modified
- 2022-03-24 18:06:20 UTC
- Schema
- 1648054861899
Issuer
- DN
- C=US, O=Entrust, Inc., OU=See www.entrust.net/legal-terms, OU=(c) 2009 Entrust, Inc. - for authorized use only, CN=Entrust Root Certification Authority - G2
- DN SHA-256
4a52f0f2755d03c6917af91b3dfb35b318d11974d77f6c48a4b3571a91e43042- Issuer DER
MIG+MQswCQYDVQQGEwJVUzEWMBQGA1UEChMNRW50cnVzdCwgSW5jLjEoMCYGA1UECxMfU2VlIHd3dy5lbnRydXN0Lm5ldC9sZWdhbC10ZXJtczE5MDcGA1UECxMwKGMpIDIwMDkgRW50cnVzdCwgSW5jLiAtIGZvciBhdXRob3JpemVkIHVzZSBvbmx5MTIwMAYDVQQDEylFbnRydXN0IFJvb3QgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkgLSBHMg==
Context
- Bugzilla
- 1761053
- Action
- On 2022-03-23, c**********l@bots.tld created a bug and proposed 15 disabled OneCRL issuer/serial additions based on revoked intermediate certificates reported in the CCADB; Dana Keeler approved staging on 2022-03-24 and production later that day.
- Confidence
- Explicit in OneCRL thread · 0.98
CCADB Link
- Issuer CA
- Entrust Root Certification Authority - G2
- CA Owner
- Sectigo
AI Summary
Generated 2026-06-30 11:41 UTC · Model: gpt-5.4-miniThis bug added 15 OneCRL entries, all disabled, corresponding to revoked intermediate certificates reported in the CCADB. The additions were generated by the ccadb2onercl bot and then reviewed by Mozilla security staff. Kathleen Wilson explicitly confirmed the entries were correct and said TLS Canary was not needed for this batch. Dana Keeler approved the changes in Kinto staging and then in production, after which the bug was resolved FIXED. The thread does not state a specific CCADB revocation field or candidate-report state beyond the fact that the certificates were revoked in CCADB. The thread also does not name a separate external compliance incident or CA closure as the cause; only the CCADB revocation report is explicitly cited.
On 2022-03-23, c**********l@bots.tld created a bug and proposed 15 disabled OneCRL issuer/serial additions based on revoked intermediate certificates reported in the CCADB; Dana Keeler approved staging on 2022-03-24 and production later that day.
Explicitly stated trigger: revoked intermediate certificates reported in the CCADB; no specific revocation field, candidate-report state, or manual-addition rationale is stated.
Unknown / not stated; the thread only references CCADB-reported revocation and does not identify a separate compliance incident, root program report, m.d.s.p. thread, or CA closure.
Explicit in OneCRL thread · 0.98
- 2022-03-23c**********l@bots.tld opened bug 1761053 and proposed OneCRL additions based on revoked intermediate certificates reported in CCADB.
- 2022-03-23Kathleen Wilson confirmed the entries were correct and said TLS Canary was not needed.
- 2022-03-24Dana Keeler approved the changes in Kinto staging.
- 2022-03-24Dana Keeler approved the changes in production.
- 2022-03-24Bug 1761053 was resolved FIXED.
AI-generated from the OneCRL record and linked Bugzilla thread. Mozilla and CCADB records remain authoritative.
Raw Remote Settings Record
{
"schema": 1648054861899,
"details": {
"bug": "https://bugzilla.mozilla.org/show_bug.cgi?id=1761053",
"who": "",
"why": "",
"name": "",
"created": ""
},
"enabled": false,
"issuerName": "MIG+MQswCQYDVQQGEwJVUzEWMBQGA1UEChMNRW50cnVzdCwgSW5jLjEoMCYGA1UECxMfU2VlIHd3dy5lbnRydXN0Lm5ldC9sZWdhbC10ZXJtczE5MDcGA1UECxMwKGMpIDIwMDkgRW50cnVzdCwgSW5jLiAtIGZvciBhdXRob3JpemVkIHVzZSBvbmx5MTIwMAYDVQQDEylFbnRydXN0IFJvb3QgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkgLSBHMg==",
"serialNumber": "HWoKeJCECRm+uJ7rxJqiiA==",
"id": "8ca0cf31-3b80-4751-a021-08f346882481",
"last_modified": 1648145180657
}