← OneCRL Browser

OneCRL Entry

f863e679-95a7-4481-a5de-11b1fddd1798

Revocation Entry

Status
disabled
Serial
05E8B34E1C5E228748824311B3C2EB57
Last Modified
2020-11-20 00:45:30 UTC
Schema
1605805277676

Issuer

DN
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root G3
DN SHA-256
3772129ef07eec41fc93eeb7786edcbc0dca3aff72f09427773458cddda5c464
Issuer DER
MGExCzAJBgNVBAYTAlVTMRUwEwYDVQQKEwxEaWdpQ2VydCBJbmMxGTAXBgNVBAsTEHd3dy5kaWdpY2VydC5jb20xIDAeBgNVBAMTF0RpZ2lDZXJ0IEdsb2JhbCBSb290IEcz

Context

Bugzilla
1678378
Action
ccadb2onercl bot added OneCRL entries for revoked intermediate certificates; the local OneCRL records show the batch was last modified on 2020-11-20T00:45:29Z-00:45:30Z, with STAGE approval at 2020-11-20T00:43:07Z and PROD approval at 2020-11-20T00:45:41Z.
Confidence
Explicit in OneCRL thread · 0.98

CCADB Link

Issuer CA
DigiCert Global Root G3
CA Owner
DigiCert

AI Summary

Generated 2026-06-30 11:41 UTC · Model: gpt-5.4-mini

This bug added a batch of OneCRL entries for revoked intermediate certificates reported in the CCADB. The additions were created by the ccadb2onercl bot and later confirmed by Kathleen Wilson as the correct entries to add. The thread states these revocations had happened a while earlier and had already been added to other root-store equivalents of OneCRL, so no TLS Canary run was needed. The OneCRL records show the entries were disabled and last modified on 2020-11-20T00:45:29Z to 2020-11-20T00:45:30Z. The bug was approved at STAGE at 2020-11-20T00:43:07Z and at PROD at 2020-11-20T00:45:41Z. The thread does not state the specific CCADB revocation fields or the external compliance incident/CA closure for these certificates.

OneCRL action

ccadb2onercl bot added OneCRL entries for revoked intermediate certificates; the local OneCRL records show the batch was last modified on 2020-11-20T00:45:29Z-00:45:30Z, with STAGE approval at 2020-11-20T00:43:07Z and PROD approval at 2020-11-20T00:45:41Z.

CCADB trigger

Explicitly stated only as revoked intermediate certificates reported in the CCADB; specific CCADB fields/candidate-report state not stated.

External cause

Unknown / not stated; the thread only says the revocations happened earlier and were already present in other root-store equivalents of OneCRL.

Confidence

Explicit in OneCRL thread · 0.98

Chronology
  • 2020-11-19ccadb2onercl bot created the bug and attached proposed OneCRL additions based on revoked intermediate certificates reported in the CCADB.
  • 2020-11-20Kathleen Wilson confirmed the entries were correct and said TLS Canary was unnecessary because the revocations were older and already in other root-store equivalents.
  • 2020-11-20The change was approved at STAGE.
  • 2020-11-20The change was approved at PROD.
  • 2021-04-15Bug was moved to Core::Security Block-lists, Allow-lists, and other State.

AI-generated from the OneCRL record and linked Bugzilla thread. Mozilla and CCADB records remain authoritative.

Raw Remote Settings Record

{
    "schema": 1605805277676,
    "details": {
        "bug": "https://bugzilla.mozilla.org/show_bug.cgi?id=1678378",
        "who": "",
        "why": "",
        "name": "",
        "created": ""
    },
    "enabled": false,
    "issuerName": "MGExCzAJBgNVBAYTAlVTMRUwEwYDVQQKEwxEaWdpQ2VydCBJbmMxGTAXBgNVBAsTEHd3dy5kaWdpY2VydC5jb20xIDAeBgNVBAMTF0RpZ2lDZXJ0IEdsb2JhbCBSb290IEcz",
    "serialNumber": "BeizThxeIodIgkMRs8LrVw==",
    "id": "f863e679-95a7-4481-a5de-11b1fddd1798",
    "last_modified": 1605833130177
}

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action