← OneCRL Browser

OneCRL Entry

f1fa7c0d-fa11-46dc-9f19-36d0ed7000f3

Revocation Entry

Status
disabled
Serial
2B891DB7F6087583
Last Modified
2021-02-09 22:05:30 UTC
Schema
1612890056792

Issuer

DN
C=ES, CN=Autoridad de Certificacion Firmaprofesional CIF A62634068
DN SHA-256
b8d3ab879dbd0b8b2f0c5b8db00ccb72a2c6c337b872510916dd2d0cc40840b8
Issuer DER
MFExCzAJBgNVBAYTAkVTMUIwQAYDVQQDDDlBdXRvcmlkYWQgZGUgQ2VydGlmaWNhY2lvbiBGaXJtYXByb2Zlc2lvbmFsIENJRiBBNjI2MzQwNjg=

Context

Bugzilla
1691771
Action
A batch of 23 issuer-and-serial-based certificate revocation entries was proposed for addition to OneCRL by the Common CA Database to OneCRL Bot on 2021-02-09T17:00:43Z, based on revoked intermediate certificates reported in the CCADB. Kathleen Wilson confirmed the entries, Dana Keeler ran onecrl-entry-checker, and Kathleen Wilson confirmed Dana approved the changes at Kinto Staging and Production on 2021-02-09. Kathleen Wilson then confirmed on 2021-02-10 that the new entries were present in Firefox Nightly and Release profiles.
Confidence
Explicit in OneCRL thread · 0.98

AI Summary

Generated 2026-06-30 11:41 UTC · Model: gpt-5.4

Bug 1691771 is a batch OneCRL case created automatically by the CCADB-to-OneCRL bot on 2021-02-09. The bot stated that it was adding entries to OneCRL based on revoked intermediate certificates reported in the CCADB. The public record here shows 23 disabled local OneCRL entries tied to this bug, covering certificates associated with DigiCert/QuoVadis, GlobalSign, SECOM Trust Systems, and Firmaprofesional. Kathleen Wilson explicitly confirmed the listed issuer/serial pairs were the correct entries to add, stated staging and production visual inspection checked out, and directed Dana Keeler to proceed with onecrl-entry-checker and approvals. Dana Keeler then provided onecrl-entry-checker output, after which Kathleen Wilson confirmed approval at Kinto Staging and Production. On 2021-02-10, Kathleen Wilson confirmed the new OneCRL entries were present in her Nightly and Release Firefox profiles. The thread does not state per-certificate CCADB revocation reasons, revocation dates, or any external compliance incident for the affected intermediates. Any linkage to specific CA incidents or closures would therefore be inference beyond the explicit OneCRL thread.

OneCRL action

A batch of 23 issuer-and-serial-based certificate revocation entries was proposed for addition to OneCRL by the Common CA Database to OneCRL Bot on 2021-02-09T17:00:43Z, based on revoked intermediate certificates reported in the CCADB. Kathleen Wilson confirmed the entries, Dana Keeler ran onecrl-entry-checker, and Kathleen Wilson confirmed Dana approved the changes at Kinto Staging and Production on 2021-02-09. Kathleen Wilson then confirmed on 2021-02-10 that the new entries were present in Firefox Nightly and Release profiles.

CCADB trigger

Explicitly stated as revoked intermediate certificates reported in the CCADB; no per-certificate revocation reason, revocation date, or candidate-report state is stated in the thread.

External cause

Unknown; the OneCRL bug thread does not state any related compliance incident, root program report, mailing-list discussion, or CA closure as the reason for these revocations.

Confidence

Explicit in OneCRL thread · 0.98

Chronology
  • 2021-02-09CCADB-to-OneCRL bot filed Bug 1691771 stating entries were being added to OneCRL based on revoked intermediate certificates reported in the CCADB.
  • 2021-02-09Bot attached issuer/serial pairs, proposed OneCRL additions, and decoded entry details.
  • 2021-02-09Kathleen Wilson confirmed the entries were correct to add to OneCRL.
  • 2021-02-09Kathleen Wilson said Kinto Staging and Production visual inspection checked out and TLS Canary was not needed for this batch.
  • 2021-02-09Dana Keeler provided onecrl-entry-checker output.
  • 2021-02-09Kathleen Wilson confirmed Dana approved at Kinto Staging and Production.
  • 2021-02-10Kathleen Wilson confirmed the new OneCRL entries were present in her Nightly and Release Firefox profiles.
  • 2021-04-15Bugzilla automation moved the bug to Core::Security Block-lists, Allow-lists, and other State.

AI-generated from the OneCRL record and linked Bugzilla thread. Mozilla and CCADB records remain authoritative.

Raw Remote Settings Record

{
    "schema": 1612890056792,
    "details": {
        "bug": "https://bugzilla.mozilla.org/show_bug.cgi?id=1691771",
        "who": "",
        "why": "",
        "name": "",
        "created": ""
    },
    "enabled": false,
    "issuerName": "MFExCzAJBgNVBAYTAkVTMUIwQAYDVQQDDDlBdXRvcmlkYWQgZGUgQ2VydGlmaWNhY2lvbiBGaXJtYXByb2Zlc2lvbmFsIENJRiBBNjI2MzQwNjg=",
    "serialNumber": "K4kdt/YIdYM=",
    "id": "f1fa7c0d-fa11-46dc-9f19-36d0ed7000f3",
    "last_modified": 1612908330256
}

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action