OneCRL Entry
ecdafe75-3436-4a5b-a54e-0bbd396587d4
Revocation Entry
- Status
- disabled
- Serial
067B50581E5545823C0BA62F6309DE5FCA494C- Last Modified
- 2021-08-05 18:17:47 UTC
- Schema
- 1628182863782
Issuer
- DN
- C=US, O=Amazon, CN=Amazon Root CA 1
- DN SHA-256
fe49d8f2a5a5b36fd054c55e96488701dbbb98f9b6ca263fb40c4a5b31d258bf- Issuer DER
MDkxCzAJBgNVBAYTAlVTMQ8wDQYDVQQKEwZBbWF6b24xGTAXBgNVBAMTEEFtYXpvbiBSb290IENBIDE=
Context
- Bugzilla
- 1724254
- Action
- On 2021-08-05, c**********l@bots.tld added 8 disabled OneCRL issuer/serial entries to the bug for staging and production approval; the changes were approved at staging by d**********r@mozilla.com and then approved in production the same day.
- Confidence
- Explicit in OneCRL thread · 0.98
CCADB Link
- Issuer CA
- Amazon Root CA 1
- CA Owner
- Amazon Trust Services
AI Summary
Generated 2026-06-30 11:41 UTC · Model: gpt-5.4-miniThis bug added 8 OneCRL entries, all disabled revocations for issuer/serial pairs reported from CCADB. The entries cover 5 Actalis Authentication Root CA serials, 2 Amazon Root CA 1 / Starfield Services Root Certificate Authority - G2 serials, and 1 E-Tugra Certification Authority serial. The action was initiated by the c**********l@bots.tld bot at 2021-08-05T17:00:52Z, which said it was adding entries based on revoked intermediate certificates reported in the CCADB. Kathleen Wilson explicitly confirmed the entries were correct and approved them for Kinto staging, and David Keeler approved them in production. The bug was then verified in Firefox Nightly and Release profiles. The thread does not state the specific CCADB revocation fields or candidate-report state that qualified these entries, beyond the bot’s statement that they came from revoked intermediates in CCADB.
On 2021-08-05, c**********l@bots.tld added 8 disabled OneCRL issuer/serial entries to the bug for staging and production approval; the changes were approved at staging by d**********r@mozilla.com and then approved in production the same day.
Explicitly stated trigger: revoked intermediate certificates reported in CCADB; no specific CCADB revocation field or candidate-report state is stated.
Unknown / not stated; the thread only says the entries were based on revoked intermediate certificates reported in CCADB and does not name a separate compliance incident or CA closure.
Explicit in OneCRL thread · 0.98
- 2021-08-05c**********l@bots.tld created the bug and began adding OneCRL entries based on revoked intermediates reported in CCADB.
- 2021-08-05Kathleen Wilson confirmed the entries were correct and said TLS Canary was not needed for this batch.
- 2021-08-05David Keeler approved the changes at staging after onecrl-entry-checker comparison.
- 2021-08-05David Keeler approved the changes in production.
- 2021-08-05Kathleen Wilson verified the changes in Firefox Nightly and Release profiles.
AI-generated from the OneCRL record and linked Bugzilla thread. Mozilla and CCADB records remain authoritative.
Raw Remote Settings Record
{
"schema": 1628182863782,
"details": {
"bug": "https://bugzilla.mozilla.org/show_bug.cgi?id=1724254",
"who": "",
"why": "",
"name": "",
"created": ""
},
"enabled": false,
"issuerName": "MDkxCzAJBgNVBAYTAlVTMQ8wDQYDVQQKEwZBbWF6b24xGTAXBgNVBAMTEEFtYXpvbiBSb290IENBIDE=",
"serialNumber": "BntQWB5VRYI8C6YvYwneX8pJTA==",
"id": "ecdafe75-3436-4a5b-a54e-0bbd396587d4",
"last_modified": 1628187467288
}