OneCRL Entry
e172b2a0-7704-4195-8210-22b6c3011640
Revocation Entry
- Status
- enabled
- Serial
00FA0C43AD50CAD53D88C3F04AF77B65C6- Last Modified
- 2019-08-21 04:14:51 UTC
- Schema
- 1566243714956
Issuer
- DN
- C=US, ST=TX, L=Houston, O=cPanel, Inc., CN=cPanel, Inc. Certification Authority
- DN SHA-256
b8ed905edcc18bf3a0c1dddfd7c6c68cea87c66bc2c48676bcda95a8a77618a3- Issuer DER
MHIxCzAJBgNVBAYTAlVTMQswCQYDVQQIEwJUWDEQMA4GA1UEBxMHSG91c3RvbjEVMBMGA1UEChMMY1BhbmVsLCBJbmMuMS0wKwYDVQQDEyRjUGFuZWwsIEluYy4gQ2VydGlmaWNhdGlvbiBBdXRob3JpdHk=
Context
- Bugzilla
- 1572287
- Action
- Two cPanel, Inc. Certification Authority certificates were added to OneCRL by w**********r@mozilla.com on 2019-08-17, with last modification on 2019-08-21; the OneCRL detail_why field says 'registry compromise'.
- Confidence
- Explicit in OneCRL thread · 0.97
CCADB Link
- Issuer CA
- cPanel, Inc. Certification Authority
- CA Owner
- Sectigo
AI Summary
Generated 2026-06-30 11:01 UTC · Model: gpt-5.4-miniWayne Thayer opened the bug on 2019-08-08 to add attacker-controlled google.tg certificates to OneCRL, citing a misissued certificate report and a likely .tg ccTLD compromise. Sectigo later clarified that the certificate was not a CA misissuance, but was issued after normal domain-control validation with an empty CAA RRset. Robin Alden of Sectigo said on 2019-08-09 that the google.tg certificate had been revoked, and the Amazon security team later led to revocation of a related amazon.tg certificate. Wayne then stated on 2019-08-22 that both certificates were now in OneCRL. The OneCRL entries show two cPanel, Inc. Certification Authority certificates, both added by w**********r@mozilla.com on 2019-08-17 and last modified on 2019-08-21, with the reason recorded as registry compromise. The thread does not state a CCADB candidate-report state or a specific CCADB revocation field as the trigger; the qualification appears to be based on the reported registry compromise and the revocations. The external cause is explicitly tied to a .tg registry compromise discussed in the bug and linked Mozilla dev-security-policy thread.
Two cPanel, Inc. Certification Authority certificates were added to OneCRL by w**********r@mozilla.com on 2019-08-17, with last modification on 2019-08-21; the OneCRL detail_why field says 'registry compromise'.
Unknown / not stated; the thread does not mention a CCADB candidate-report state or specific revocation field, only that the OneCRL entries were added for registry compromise after revocation.
Explicitly linked .tg registry compromise affecting attacker-controlled certificates; no CA closure is stated.
Explicit in OneCRL thread · 0.97
- 2019-08-08Wayne Thayer filed Bug 1572287 to add attacker-controlled google.tg certificates to OneCRL.
- 2019-08-09Sectigo said the google.tg certificate had been revoked; later the Amazon security team led to revocation of amazon.tg.
- 2019-08-17Two cPanel CA certificates were created in OneCRL by w**********r@mozilla.com with reason 'registry compromise'.
- 2019-08-21The OneCRL entries were last modified.
- 2019-08-22Wayne Thayer stated that the two certificates were now in OneCRL.
AI-generated from the OneCRL record and linked Bugzilla thread. Mozilla and CCADB records remain authoritative.
Raw Remote Settings Record
{
"schema": 1566243714956,
"details": {
"bug": "https://bugzilla.mozilla.org/show_bug.cgi?id=1572287",
"who": "wthayer@mozilla.com",
"why": "registry compromise",
"name": "",
"created": "2019-08-17T19:34:58Z"
},
"enabled": true,
"issuerName": "MHIxCzAJBgNVBAYTAlVTMQswCQYDVQQIEwJUWDEQMA4GA1UEBxMHSG91c3RvbjEVMBMGA1UEChMMY1BhbmVsLCBJbmMuMS0wKwYDVQQDEyRjUGFuZWwsIEluYy4gQ2VydGlmaWNhdGlvbiBBdXRob3JpdHk=",
"serialNumber": "APoMQ61QytU9iMPwSvd7ZcY=",
"id": "e172b2a0-7704-4195-8210-22b6c3011640",
"last_modified": 1566360891835
}