GRCA: Signing SHA-1 OCSP responses with unconstrained certificate
The Government of Taiwan's Government Root Certification Authority (GRCA) was reported for signing OCSP responses with SHA-1 using an unconstrained certificate, violating Mozilla's Root Store Policy. The issue was identified through a Bugzilla report on September 23, 2017. GRCA acknowledged the problem, stating that a subordinate CA, HCA, misunderstood the SHA-1 deprecation policy. They took corrective actions, including stopping the use of SHA-1 for OCSP responses by September 30, 2017, and have committed to improving compliance communication with subordinate CAs. The bug has been resolved as the issue was fixed.
- Incident identified via Bugzilla report.
- HCA stopped generating SHA-1 OCSP responses.
- Mm representative — Reported SHA-1 OCSP signing issue to GRCA.
- Mozilla representative — Requested prompt acknowledgment and incident report from GRCA.
- Ndc representative — GRCA provided an incident report detailing the timeline and corrective actions.
- Ndc representative — Confirmed that SHA-1 OCSP signing has ceased.
- Mozilla representative — Confirmed that the bug can be made public.