GRCA misissued certificates with invalid commonName values and delayed revocation/remediation
This case concerns GRCA-issued TLS certificates whose commonName field improperly concatenated multiple SAN entries with semicolons, resulting in invalid commonName values and commonName values not present in SAN. Mozilla requested an incident report, a timeline, and details on affected certificates and revocation. GRCA said it discovered the issue internally, stopped the multi-domain certificate service on 2018-05-07, fixed the problem on 2018-05-10, and identified 88 affected certificates issued between 2018-01-07 and 2018-05-07. GRCA initially planned to revoke the affected certificates by 2019-02-28, later reported that all affected certificates were revoked on 2019-03-04 because of Taiwan holidays, and described follow-up changes including automated certificate checks and later system changes to generate the CN field automatically. The bug was ultimately resolved and later closed after removal of the root certificate from NSS.
- GRCA began issuing multi-domain certificates with multiple domains concatenated into the commonName field.
- GRCA discovered the issue and stopped the multi-domain certificate service.
- GRCA fixed the certificate format issue and resumed the service.
- GRCA revoked all affected certificates.
- Mozilla closed the bug as resolved by removal of the root certificate from NSS.
- Community commenter — Reported example certificates and said they improperly concatenated multiple SANs into the commonName using semicolons.
- Community commenter — Asked GRCA to acknowledge the bug promptly, provide a resolution timeline, and submit an incident report.
- Ndc representative — Said GRCA found the issue internally, stopped the service on 2018-05-07, fixed it on 2018-05-10, identified 88 affected certificates, and planned revocation by 2019-02-28.
- Ndc representative — Attached the incident report and affected certificate list.
- Community commenter — Asked for a stronger root cause analysis and for steps to prevent recurrence.
- Ndc representative — Explained that technicians thought the CN field was no longer effective, said they had tested with browsers but not automated certificate tools, and committed to adding cablint/x509lint/zlint checks.
- Ndc representative — Reported that all affected certificates were revoked on 2019-03-04 because 2019-02-28 to 2019-03-03 were holidays in Taiwan.
- Ndc representative — Said a new checking mechanism was implemented and that the CN field is now generated by system rather than manually.
- Ndc representative — Said GRCA and its hierarchy would stop issuing TLS certificates after 2019-09-18 and that all TLS certificates would be revoked by 2020-07-19.
- Ndc representative — Confirmed that GRCA and its sub-CAs had not issued TLS certificates since 2019-09-18 and did not issue S/MIME certificates.
- Mozilla representative — Summarized the intended root changes, including distrust-after for TLS and removal of the Email trust bit.
- Ndc representative — Asked for more time and requested that the root certificate be removed after 2020-07-19.
- Mozilla representative — Closed the bug as resolved by removal of the root certificate from NSS.