OneCRL Entry
c260bac4-affa-44d2-b24b-adfc5554c274
Revocation Entry
- Status
- disabled
- Serial
2FE0C106450ED3680C51029C8C54125D- Last Modified
- 2021-08-05 18:17:47 UTC
- Schema
- 1628182862133
Issuer
- DN
- C=IT, L=Milan, O=Actalis S.p.A./03358520967, CN=Actalis Authentication Root CA
- DN SHA-256
02b7fea4088dcc670549c2202e8c9ee89e50349368c0dd3c115a9a6c716022aa- Issuer DER
MGsxCzAJBgNVBAYTAklUMQ4wDAYDVQQHDAVNaWxhbjEjMCEGA1UECgwaQWN0YWxpcyBTLnAuQS4vMDMzNTg1MjA5NjcxJzAlBgNVBAMMHkFjdGFsaXMgQXV0aGVudGljYXRpb24gUm9vdCBDQQ==
Context
- Bugzilla
- 1724254
- Action
- On 2021-08-05, c**********l@bots.tld added 8 disabled OneCRL issuer/serial entries to the bug for staging and production approval; the changes were approved at staging by d**********r@mozilla.com and then approved in production the same day.
- Confidence
- Explicit in OneCRL thread · 0.98
CCADB Link
- Issuer CA
- Actalis Authentication Root CA
- CA Owner
- Actalis
AI Summary
Generated 2026-06-30 11:41 UTC · Model: gpt-5.4-miniThis bug added 8 OneCRL entries, all disabled revocations for issuer/serial pairs reported from CCADB. The entries cover 5 Actalis Authentication Root CA serials, 2 Amazon Root CA 1 / Starfield Services Root Certificate Authority - G2 serials, and 1 E-Tugra Certification Authority serial. The action was initiated by the c**********l@bots.tld bot at 2021-08-05T17:00:52Z, which said it was adding entries based on revoked intermediate certificates reported in the CCADB. Kathleen Wilson explicitly confirmed the entries were correct and approved them for Kinto staging, and David Keeler approved them in production. The bug was then verified in Firefox Nightly and Release profiles. The thread does not state the specific CCADB revocation fields or candidate-report state that qualified these entries, beyond the bot’s statement that they came from revoked intermediates in CCADB.
On 2021-08-05, c**********l@bots.tld added 8 disabled OneCRL issuer/serial entries to the bug for staging and production approval; the changes were approved at staging by d**********r@mozilla.com and then approved in production the same day.
Explicitly stated trigger: revoked intermediate certificates reported in CCADB; no specific CCADB revocation field or candidate-report state is stated.
Unknown / not stated; the thread only says the entries were based on revoked intermediate certificates reported in CCADB and does not name a separate compliance incident or CA closure.
Explicit in OneCRL thread · 0.98
- 2021-08-05c**********l@bots.tld created the bug and began adding OneCRL entries based on revoked intermediates reported in CCADB.
- 2021-08-05Kathleen Wilson confirmed the entries were correct and said TLS Canary was not needed for this batch.
- 2021-08-05David Keeler approved the changes at staging after onecrl-entry-checker comparison.
- 2021-08-05David Keeler approved the changes in production.
- 2021-08-05Kathleen Wilson verified the changes in Firefox Nightly and Release profiles.
AI-generated from the OneCRL record and linked Bugzilla thread. Mozilla and CCADB records remain authoritative.
Raw Remote Settings Record
{
"schema": 1628182862133,
"details": {
"bug": "https://bugzilla.mozilla.org/show_bug.cgi?id=1724254",
"who": "",
"why": "",
"name": "",
"created": ""
},
"enabled": false,
"issuerName": "MGsxCzAJBgNVBAYTAklUMQ4wDAYDVQQHDAVNaWxhbjEjMCEGA1UECgwaQWN0YWxpcyBTLnAuQS4vMDMzNTg1MjA5NjcxJzAlBgNVBAMMHkFjdGFsaXMgQXV0aGVudGljYXRpb24gUm9vdCBDQQ==",
"serialNumber": "L+DBBkUO02gMUQKcjFQSXQ==",
"id": "c260bac4-affa-44d2-b24b-adfc5554c274",
"last_modified": 1628187467316
}