← Government of Taiwan, Government Root Certification Authority (GRCA) cases
Bugzilla #1463975 Certificate Misissuance

GRCA: Misissued certificates: Invalid commonName, commonName not in SAN

RESOLVED FIXED Government of Taiwan, Government Root Certification Authority (GRCA)
AI Summary

The Government Root Certification Authority (GRCA) misissued 88 certificates with an invalid commonName format, concatenating multiple Subject Alternative Names (SANs) into the commonName field. The issue was identified on May 7, 2018, and the service was halted shortly thereafter. GRCA committed to revoke the affected certificates by February 28, 2019, but the revocation was completed on March 4, 2019, due to holiday delays. An incident report was filed detailing the misissuance and the steps taken to prevent future occurrences.

Model: gpt-4o-mini Generated: 2026-06-13 17:49 UTC Confidence: 1.00
Chronology
  1. Issue identified and multi-domain certificate service stopped.
  2. Issue fixed.
  3. Incident report created.
  4. Scheduled revocation date for affected certificates.
  5. All affected certificates revoked.
Participants
Ryan Sleevi Wayne Thayer National Development Council
Similar Local Cases
#1523221 RESOLVED Certificate Misissuance Opened 2019-01-28 · Closed 2023-02-22 · 59% similar
GRCA: Misissued certificates - invalid CN, bad validity period, missing extensions
#1462423 RESOLVED Certificate Misissuance Opened 2018-05-17 · Closed 2023-02-22 · 59% similar
NetLock: CN not in SAN
#1462844 RESOLVED Certificate Misissuance Opened 2018-05-19 · Closed 2023-02-22 · 59% similar
GoDaddy: Improper DER results in failure to comply with RFC 5280 - Invalid characters in PrintableString
#1524871 RESOLVED Certificate Misissuance Opened 2019-02-03 · Closed 2023-02-22 · 58% similar
Camerfirma: failure to revoke underscores
#1520299 RESOLVED Certificate Misissuance Opened 2019-01-15 · Closed 2023-02-22 · 58% similar
Hongkong Post / Certizen: Failure to report misissuance
#1548714 RESOLVED Certificate Misissuance Opened 2019-05-02 · Closed 2023-02-22 · 57% similar
SECOM: "Default City" in Subject:localityName
#1532436 RESOLVED Certificate Misissuance Opened 2019-03-04 · Closed 2023-02-22 · 57% similar
Chunghwa Telecom: Test certificate with unregistered domain name
#1551363 RESOLVED Certificate Misissuance Opened 2019-05-14 · Closed 2023-02-22 · 57% similar
DigiCert: "Some-State" in stateOrProvinceName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action