← Government of Taiwan, Government Root Certification Authority (GRCA) cases
Bugzilla #1397832
Certificate Problem Report
GRCA: Signing SHA-1 OCSP responses with unconstrained certificate
RESOLVED
FIXED
Government of Taiwan, Government Root Certification Authority (GRCA)
AI Summary
The Government Root Certification Authority (GRCA) was found to be signing OCSP responses with SHA-1, which violates Mozilla's Root Store Policy. The issue was reported on September 7, 2017, and GRCA acknowledged the problem, stating that a subordinate CA misunderstood the policy. GRCA took corrective actions, including stopping the use of SHA-1 for OCSP responses by September 30, 2017. The case was resolved on February 22, 2023, after confirming compliance with the policy.
Chronology
- Bug reported regarding SHA-1 OCSP responses.
- GRCA identified the incident.
- GRCA confirmed the issue was fixed.
- Bug resolved after compliance confirmation.
Participants
Andrew Ayer
Kathleen Wilson
Gervase Markham
Hung-Yu Hsu
Rob Betwu
External References
Similar Local Cases
GlobalSign: Incapsula issued a certificate for non-existing domain (testslsslfeb20.me)
SECOM: Non-BR-Compliant OCSP Responders
Visa: Non-BR-Compliant Certificate Issuance
Camerfirma: Startcom are issuing by proxy using Camerfirma
GoDaddy: New GoDaddy incorrect issuance bug appears to be regression of 2010 issue
Investigate *.google.com certificate issued by DigiNotar and used by Iran government?
Camerfirma: Non-BR-Compliant Certificate Issuance
LuxTrust: issuing 1024 bit certificates