OneCRL Entry
8f26fd75-b45a-451d-b518-85636b5eb118
Revocation Entry
- Status
- disabled
- Serial
4A103DB3E1D92662652B3BDC6AE5C2F3- Last Modified
- 2021-11-10 23:42:56 UTC
- Schema
- 1636563665753
Issuer
- DN
- C=DE, O=D-Trust GmbH, CN=D-TRUST Root Class 3 CA 2 EV 2009
- DN SHA-256
7439080e91429d452f406f62dea2d8c7fdad830e0f10486b83cdd34bcd649177- Issuer DER
MFAxCzAJBgNVBAYTAkRFMRUwEwYDVQQKDAxELVRydXN0IEdtYkgxKjAoBgNVBAMMIUQtVFJVU1QgUm9vdCBDbGFzcyAzIENBIDIgRVYgMjAwOQ==
Context
- Bugzilla
- 1740553
- Action
- 18 disabled issuer/serial entries were added to OneCRL by the ccadb2onercl bot from CCADB-reported revoked intermediate certificates; proposed on 2021-11-10T17:00:47Z, approved at staging on 2021-11-10T23:21:31Z, approved at production on 2021-11-10T23:43:26Z, and verified on 2021-11-11T00:12:44Z.
- Confidence
- Explicit in OneCRL thread · 0.98
CCADB Link
- Issuer CA
- D-TRUST Root Class 3 CA 2 EV 2009
- CA Owner
- D-TRUST
AI Summary
Generated 2026-06-30 11:41 UTC · Model: gpt-5.4-miniThis bug added 18 OneCRL entries, all disabled revocations for issuer/serial pairs, and the changes were generated by the ccadb2onercl bot from CCADB data. The bot opened the bug on 2021-11-10T17:00:47Z and attached the proposed OneCRL additions and decoded issuer/serial lists. Mozilla reviewer Kathleen Wilson confirmed the entries were correct and said TLS Canary was not needed for this batch. David Keeler approved the changes at staging on 2021-11-10T23:21:31Z and at production on 2021-11-10T23:43:26Z, and Kathleen Wilson verified them in Firefox Nightly and Release on 2021-11-11T00:12:44Z. The thread explicitly says the additions were based on revoked intermediate certificates reported in the CCADB. The thread does not state the specific CCADB revocation fields, candidate-report state, or the underlying external compliance incident for these certificates. Several of the added entries are for SECOM Trust Systems and D-TRUST roots, plus one NetLock root, but no closure or incident explanation is given in the bug thread.
18 disabled issuer/serial entries were added to OneCRL by the ccadb2onercl bot from CCADB-reported revoked intermediate certificates; proposed on 2021-11-10T17:00:47Z, approved at staging on 2021-11-10T23:21:31Z, approved at production on 2021-11-10T23:43:26Z, and verified on 2021-11-11T00:12:44Z.
Explicitly stated trigger: revoked intermediate certificates reported in the CCADB; specific CCADB fields, revocation date, or candidate-report state not stated.
Unknown / not stated; the thread does not identify a specific compliance incident, root program report, m.d.s.p. thread, or CA closure.
Explicit in OneCRL thread · 0.98
- 2021-11-10ccadb2onercl bot created Bug 1740553 and said it was adding OneCRL entries based on revoked intermediate certificates reported in CCADB.
- 2021-11-10Bot attached proposed OneCRL additions and decoded issuer/serial lists.
- 2021-11-10Kathleen Wilson confirmed the entries were correct and said TLS Canary was not needed.
- 2021-11-10David Keeler approved the changes at staging.
- 2021-11-10David Keeler approved the changes at production.
- 2021-11-11Kathleen Wilson verified the changes in Firefox Nightly and Release profiles.
AI-generated from the OneCRL record and linked Bugzilla thread. Mozilla and CCADB records remain authoritative.
Raw Remote Settings Record
{
"schema": 1636563665753,
"details": {
"bug": "https://bugzilla.mozilla.org/show_bug.cgi?id=1740553",
"who": "",
"why": "",
"name": "",
"created": ""
},
"enabled": false,
"issuerName": "MFAxCzAJBgNVBAYTAkRFMRUwEwYDVQQKDAxELVRydXN0IEdtYkgxKjAoBgNVBAMMIUQtVFJVU1QgUm9vdCBDbGFzcyAzIENBIDIgRVYgMjAwOQ==",
"serialNumber": "ShA9s+HZJmJlKzvcauXC8w==",
"id": "8f26fd75-b45a-451d-b518-85636b5eb118",
"last_modified": 1636587776778
}