← OneCRL Browser

OneCRL Entry

d52d566d-3170-4de0-9b72-480f29a507cb

Revocation Entry

Status
disabled
Serial
22B9B176817E3637C555F5C42D4C36BF
Last Modified
2021-04-09 22:35:40 UTC
Schema
1617814862028

Issuer

DN
C=JP, O=SECOM Trust Systems CO.,LTD., OU=Security Communication RootCA2
DN SHA-256
42a64d1b796fbf88b987504ad560eaa1e46777712ae4042ba8f8713d831f6849
Issuer DER
MF0xCzAJBgNVBAYTAkpQMSUwIwYDVQQKExxTRUNPTSBUcnVzdCBTeXN0ZW1zIENPLixMVEQuMScwJQYDVQQLEx5TZWN1cml0eSBDb21tdW5pY2F0aW9uIFJvb3RDQTI=

Context

Bugzilla
1703616
Action
A batch of issuer/serial revocation entries for multiple revoked intermediate certificates was proposed for addition to OneCRL by the Common CA Database to OneCRL Bot on 2021-04-07T17:00:50Z, confirmed by Kathleen Wilson on 2021-04-08, approved in Kinto staging and then production by Dana Keeler on 2021-04-08 and 2021-04-09, and confirmed present in Firefox profiles on 2021-04-10.
Confidence
Explicit in OneCRL thread · 0.98

AI Summary

Generated 2026-06-30 11:41 UTC · Model: gpt-5.4

This Bugzilla case tracks a batch addition of revoked intermediate certificate entries to Mozilla OneCRL. The bug was created automatically by the Common CA Database to OneCRL Bot on 2021-04-07, and the opening comment states the entries were being added based on revoked intermediate certificates reported in the CCADB. Kathleen Wilson explicitly confirmed on 2021-04-08 that the listed entries were the correct ones to add to OneCRL and said TLS Canary was not needed for this set of changes. Dana Keeler then approved the changes in staging, later confirmed staging looked correct, ran the onecrl-entry-checker tool at Kathleen's request, and approved the changes for production on 2021-04-09. Kathleen confirmed on 2021-04-10 that the new OneCRL entries were present in her Nightly and Release Firefox profiles. The local OneCRL entry list tied to this bug contains multiple issuer/serial revocation entries across several CA owners, including SECOM Trust Systems, GlobalSign, DigiCert/Baltimore, and Chunghwa Telecom. The thread does not state per-certificate revocation reasons, revocation dates, or any external compliance incident or CA closure explaining why those intermediates had been revoked. Any more specific trigger beyond revoked intermediate status in CCADB would be inference rather than explicit fact from this thread.

OneCRL action

A batch of issuer/serial revocation entries for multiple revoked intermediate certificates was proposed for addition to OneCRL by the Common CA Database to OneCRL Bot on 2021-04-07T17:00:50Z, confirmed by Kathleen Wilson on 2021-04-08, approved in Kinto staging and then production by Dana Keeler on 2021-04-08 and 2021-04-09, and confirmed present in Firefox profiles on 2021-04-10.

CCADB trigger

Explicitly stated as revoked intermediate certificates reported in the CCADB; no per-entry revocation reason, revocation date, candidate-report state, or manual-addition rationale is stated in the thread.

External cause

Unknown; the thread does not cite any related compliance incident, root program report, mailing list discussion, or CA closure as the reason these intermediates were revoked.

Confidence

Explicit in OneCRL thread · 0.98

Chronology
  • 2021-04-07Bug 1703616 was created by the Common CA Database to OneCRL Bot.
  • 2021-04-07Bot stated entries were being added to OneCRL based on revoked intermediate certificates reported in the CCADB.
  • 2021-04-07Bot attached issuer/serial pairs, proposed OneCRL additions, and decoded entry details.
  • 2021-04-08Bot posted that the changes were still in review.
  • 2021-04-08Kathleen Wilson confirmed the entries were correct and said TLS Canary was not needed.
  • 2021-04-08Dana Keeler approved the changes in staging.
  • 2021-04-09Bot again posted that the changes were still in review.
  • 2021-04-09Dana Keeler said staging looked correct.
  • 2021-04-09Kathleen Wilson requested onecrl-entry-checker output.
  • 2021-04-09Dana Keeler attached onecrl-entry-checker output.
  • 2021-04-09Kathleen Wilson said the output looked correct and requested production approval.
  • 2021-04-09Dana Keeler approved the changes for production.
  • 2021-04-10Kathleen Wilson confirmed the new OneCRL entries were present in her Nightly and Release Firefox profiles.
  • 2021-04-15Automation moved the bug to Core::Security Block-lists, Allow-lists, and other State.

AI-generated from the OneCRL record and linked Bugzilla thread. Mozilla and CCADB records remain authoritative.

Raw Remote Settings Record

{
    "schema": 1617814862028,
    "details": {
        "bug": "https://bugzilla.mozilla.org/show_bug.cgi?id=1703616",
        "who": "",
        "why": "",
        "name": "",
        "created": ""
    },
    "enabled": false,
    "issuerName": "MF0xCzAJBgNVBAYTAkpQMSUwIwYDVQQKExxTRUNPTSBUcnVzdCBTeXN0ZW1zIENPLixMVEQuMScwJQYDVQQLEx5TZWN1cml0eSBDb21tdW5pY2F0aW9uIFJvb3RDQTI=",
    "serialNumber": "IrmxdoF+NjfFVfXELUw2vw==",
    "id": "d52d566d-3170-4de0-9b72-480f29a507cb",
    "last_modified": 1618007740359
}

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action