← OneCRL Browser

Symantec erroneous SHA-1 certificates

bbcfc451-2fcc-b380-e579-bb6d11fc7d34

Revocation Entry

Status
enabled
Serial
54DDB27857B1C978CF7F7E1F1C699B86
Last Modified
2016-11-28 16:06:04 UTC
Schema
1552493030646

Issuer

DN
C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)10, CN=VeriSign Class 3 International Server CA - G3
DN SHA-256
0ca28e71d04c14a9d6b4dbc8cbf6ed4c205925e4829d0ca030f6863944deab40
Issuer DER
MIG8MQswCQYDVQQGEwJVUzEXMBUGA1UEChMOVmVyaVNpZ24sIEluYy4xHzAdBgNVBAsTFlZlcmlTaWduIFRydXN0IE5ldHdvcmsxOzA5BgNVBAsTMlRlcm1zIG9mIHVzZSBhdCBodHRwczovL3d3dy52ZXJpc2lnbi5jb20vcnBhIChjKTEwMTYwNAYDVQQDEy1WZXJpU2lnbiBDbGFzcyAzIEludGVybmF0aW9uYWwgU2VydmVyIENBIC0gRzM=

Context

Bugzilla
1286752
Action
Eight OneCRL blocklist entries were added for the issuer VeriSign Class 3 International Server CA - G3, initiated by Mark Goodwin (:mgoodwin) on 2016-07-14 and processed by Andrew Williamson (:eviljeff) with confirmation by Jason Thomas.
Confidence
Explicit in OneCRL thread · 0.98

AI Summary

Generated 2026-06-30 11:47 UTC · Model: gpt-5.4-mini

Mozilla added eight OneCRL blocklist entries for Symantec erroneously produced and issued SHA-1 certificates. The entries all use the same issuer, VeriSign Class 3 International Server CA - G3, and were added as serial/issuer pairs. The action was initiated by Mark Goodwin (:mgoodwin) in Bugzilla, who cited the dev-security-policy mailing list thread and posted the serials on 2016-07-14. Andrew Williamson (:eviljeff) then created the certificate list attachment and requested processing, and Jason Thomas confirmed it was done. The OneCRL records show the entries were created on 2016-07-14 and last modified on 2016-11-28, but the thread does not state a CCADB revocation field or candidate-report state. The external cause is explicit in the bug title and linked thread: Symantec had erroneously produced and issued the SHA-1 certificates.

OneCRL action

Eight OneCRL blocklist entries were added for the issuer VeriSign Class 3 International Server CA - G3, initiated by Mark Goodwin (:mgoodwin) on 2016-07-14 and processed by Andrew Williamson (:eviljeff) with confirmation by Jason Thomas.

CCADB trigger

Unknown / not stated; the thread does not mention a CCADB revocation field, candidate report, or manual-add qualification beyond the blocklist request itself.

External cause

Symantec erroneously produced and issued SHA-1 certificates, as stated in the Bugzilla summary and linked dev-security-policy thread.

Confidence

Explicit in OneCRL thread · 0.98

Chronology
  • 2016-07-14Mark Goodwin opened Bugzilla 1286752 to add blocklist entries for eight Symantec erroneous SHA-1 certificates.
  • 2016-07-14Andrew Williamson created an attachment listing the certs as serial/issuer pairs and asked Jason to run the processing script.
  • 2016-07-14Jason Thomas replied 'Done.'
  • 2016-11-28The OneCRL entries show last_modified_at timestamps on this date.

AI-generated from the OneCRL record and linked Bugzilla thread. Mozilla and CCADB records remain authoritative.

Raw Remote Settings Record

{
    "schema": 1552493030646,
    "details": {
        "bug": "https://bugzilla.mozilla.org/show_bug.cgi?id=1286752",
        "who": ".",
        "why": ".",
        "name": "Symantec erroneous SHA-1 certificates",
        "created": "2016-07-14T14:40:23Z"
    },
    "enabled": true,
    "issuerName": "MIG8MQswCQYDVQQGEwJVUzEXMBUGA1UEChMOVmVyaVNpZ24sIEluYy4xHzAdBgNVBAsTFlZlcmlTaWduIFRydXN0IE5ldHdvcmsxOzA5BgNVBAsTMlRlcm1zIG9mIHVzZSBhdCBodHRwczovL3d3dy52ZXJpc2lnbi5jb20vcnBhIChjKTEwMTYwNAYDVQQDEy1WZXJpU2lnbiBDbGFzcyAzIEludGVybmF0aW9uYWwgU2VydmVyIENBIC0gRzM=",
    "serialNumber": "VN2yeFexyXjPf34fHGmbhg==",
    "id": "bbcfc451-2fcc-b380-e579-bb6d11fc7d34",
    "last_modified": 1480349164463
}

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action