← Government of Taiwan, Government Root Certification Authority (GRCA) cases
Bugzilla #1397832 Self Incident Disclosure

GRCA: Signing SHA-1 OCSP responses with unconstrained certificate

RESOLVED FIXED Government of Taiwan, Government Root Certification Authority (GRCA)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The Government of Taiwan's Government Root Certification Authority (GRCA) was reported for signing OCSP responses with SHA-1 using an unconstrained certificate, violating Mozilla's Root Store Policy. The issue was identified through a Bugzilla report on September 23, 2017. GRCA acknowledged the problem, stating that a subordinate CA, HCA, misunderstood the SHA-1 deprecation policy. They took corrective actions, including stopping the use of SHA-1 for OCSP responses by September 30, 2017, and have committed to improving compliance communication with subordinate CAs. The bug has been resolved as the issue was fixed.

Model: gpt-4o-mini Generated: 2026-06-13 17:08 UTC Revised: 2026-06-16 19:09 UTC Confidence: 0.90 14 comments
Chronology
  1. Incident identified via Bugzilla report.
  2. HCA stopped generating SHA-1 OCSP responses.
Thread Activity
  1. Mm representative — Reported SHA-1 OCSP signing issue to GRCA.
  2. Mozilla representative — Requested prompt acknowledgment and incident report from GRCA.
  3. Ndc representative — GRCA provided an incident report detailing the timeline and corrective actions.
  4. Ndc representative — Confirmed that SHA-1 OCSP signing has ceased.
  5. Mozilla representative — Confirmed that the bug can be made public.
Participants
Mm representative Mozilla representative Ndc representative
External References
Similar Local Cases
#1523221 RESOLVED Ca Certificate Compliance Opened 2019-01-28 · Closed 2023-02-22 · 56% similar
GRCA: Misissued certificates - invalid CN, bad validity period, missing extensions
#1398259 RESOLVED Self Reported Incident Incident Closure Request Opened 2017-09-08 · Closed 2023-02-22 · 42% similar
SECOM: Non-BR-Compliant OCSP Responders
#1060863 RESOLVED Remediation Tracking Opened 2014-08-30 · Closed 2022-11-14 · 42% similar
LuxTrust: issuing 1024 bit certificates
#1398247 RESOLVED Ca Certificate Compliance Opened 2017-09-08 · Closed 2023-02-22 · 42% similar
DocuSign/Keynectis: Non-BR-Compliant OCSP Responders
#1391087 RESOLVED Self Reported Incident Opened 2017-08-16 · Closed 2023-02-22 · 41% similar
Visa: Non-BR-Compliant Certificate Issuance
#1391066 RESOLVED Ca Certificate Compliance Opened 2017-08-16 · Closed 2023-02-22 · 41% similar
SwissSign: Non-BR-Compliant Certificate Issuance
#1350615 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2017-03-25 · Closed 2022-11-14 · 41% similar
Camerfirma: Startcom are issuing by proxy using Camerfirma
#1018158 RESOLVED Ca Certificate Root Program Opened 2014-05-30 · Closed 2022-11-14 · 41% similar
GRCA publicly disclosed subordinate CA certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action