View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 0000901 | XMB1 | Bugs | public | 2026-05-29 03:52 | 2026-05-30 14:47 |
| Reporter | miqrogroove | Assigned To | miqrogroove | ||
| Priority | urgent | Severity | minor | Reproducibility | have not tried |
| Status | resolved | Resolution | fixed | ||
| Product Version | 1.9.12.04 | ||||
| Target Version | 1.10.05 | Fixed in Version | 1.10.05 | ||
| Summary | 0000901: Google Requires Pinned Certificate Change Before June 15 | ||||
| Description | Many services, including googleapis.com, will shift to using the Google Trust Services WE1 intermediate and ECDSA based TLS certificates. Potential impact: If your client applications are not configured correctly, they may be unable to connect to Google services after this change. Connection failures are most likely to occur in the following two scenarios: Certificate pinning: We do not recommend pinning intermediate or leaf certificates. This practice will cause your application to break during routine certificate rotations. Custom trust stores: If you use a custom trust store, you must ensure it includes all of Google Trust Services (GTS) Root CAs to prevent outages. For most customers, no action is required as a result of this change. However, if you run a custom trust store or pin CAs, you may need to take action. We’ve provided additional information to guide you through this change. What you need to do Action advised before June 15, 2026: Ensure you trust all Google Trust Services Root CAs as detailed in this Google Trust Services Certificates documentation. Pinning is discouraged. If you choose to pin, ensure that all Google Trust Services Roots and, if applicable, intermediates are in your pin list. Timeline: Services will shift to new intermediates throughout late Q2 2026. Impacted customers/accounts: Any cloud project using a limited set of trusted roots or pinning certificates may experience issues. We’re here to help Please review the Google Trust Services announcement for guidance on ensuring reliable connections to Google services. If you have any questions or require assistance, please contact Google Cloud Support. Thanks for choosing Google Cloud. — The Google Cloud Team | ||||
| Additional Information | https://pki.goog/faq/#connecting-to-google | ||||
| Tags | No tags attached. | ||||
| MySQL Version | |||||
| PHP Version | |||||
| Web Server | |||||
| Browser | |||||
| Flags | |||||
| Original Reporter | |||||
| SVN Revision | |||||
| Git Commit | https://github.com/miqrogroove/xmb/commit/887065a45a2fa0cc80f23d08b2bc82b95a2030ba | ||||
| related to | 0000905 | resolved | miqrogroove | Google Requires Pinned Certificate Change Before June 15 |
|
|
This problem is confirmed. The intermediate CA mentioned in the recent email is signed by the GTS Root R4, but we only trust GTS Root R1. |
| Date Modified | Username | Field | Change |
|---|---|---|---|
| 2026-05-29 03:52 | miqrogroove | New Issue | |
| 2026-05-29 03:54 | miqrogroove | Additional Information Updated | |
| 2026-05-29 03:54 | miqrogroove | Additional Information Updated | |
| 2026-05-30 14:30 | miqrogroove | Assigned To | => miqrogroove |
| 2026-05-30 14:30 | miqrogroove | Status | new => assigned |
| 2026-05-30 14:30 | miqrogroove | Note Added: 0000618 | |
| 2026-05-30 14:39 | miqrogroove | Status | assigned => resolved |
| 2026-05-30 14:39 | miqrogroove | Resolution | open => fixed |
| 2026-05-30 14:39 | miqrogroove | Fixed in Version | => 1.10.05 |
| 2026-05-30 14:39 | miqrogroove | Git Commit | => https://github.com/miqrogroove/xmb/commit/887065a45a2fa0cc80f23d08b2bc82b95a2030ba |
| 2026-05-30 14:41 | miqrogroove | Product Version | => 1.9.12.04 |
| 2026-05-30 14:47 | miqrogroove | Issue cloned: 0000905 | |
| 2026-05-30 14:47 | miqrogroove | Relationship added | related to 0000905 |