← Government of Taiwan, Government Root Certification Authority (GRCA) cases
Bugzilla #1463975 Certificate Misissuance Delayed Revocation

GRCA misissued certificates with invalid commonName values and delayed revocation/remediation

RESOLVED FIXED Government of Taiwan, Government Root Certification Authority (GRCA)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns GRCA-issued TLS certificates whose commonName field improperly concatenated multiple SAN entries with semicolons, resulting in invalid commonName values and commonName values not present in SAN. Mozilla requested an incident report, a timeline, and details on affected certificates and revocation. GRCA said it discovered the issue internally, stopped the multi-domain certificate service on 2018-05-07, fixed the problem on 2018-05-10, and identified 88 affected certificates issued between 2018-01-07 and 2018-05-07. GRCA initially planned to revoke the affected certificates by 2019-02-28, later reported that all affected certificates were revoked on 2019-03-04 because of Taiwan holidays, and described follow-up changes including automated certificate checks and later system changes to generate the CN field automatically. The bug was ultimately resolved and later closed after removal of the root certificate from NSS.

Model: gpt-5.4-mini Generated: 2026-06-13 17:49 UTC Revised: 2026-06-16 19:10 UTC Confidence: 0.98 33 comments
Chronology
  1. GRCA began issuing multi-domain certificates with multiple domains concatenated into the commonName field.
  2. GRCA discovered the issue and stopped the multi-domain certificate service.
  3. GRCA fixed the certificate format issue and resumed the service.
  4. GRCA revoked all affected certificates.
  5. Mozilla closed the bug as resolved by removal of the root certificate from NSS.
Thread Activity
  1. Community commenter — Reported example certificates and said they improperly concatenated multiple SANs into the commonName using semicolons.
  2. Community commenter — Asked GRCA to acknowledge the bug promptly, provide a resolution timeline, and submit an incident report.
  3. Ndc representative — Said GRCA found the issue internally, stopped the service on 2018-05-07, fixed it on 2018-05-10, identified 88 affected certificates, and planned revocation by 2019-02-28.
  4. Ndc representative — Attached the incident report and affected certificate list.
  5. Community commenter — Asked for a stronger root cause analysis and for steps to prevent recurrence.
  6. Ndc representative — Explained that technicians thought the CN field was no longer effective, said they had tested with browsers but not automated certificate tools, and committed to adding cablint/x509lint/zlint checks.
  7. Ndc representative — Reported that all affected certificates were revoked on 2019-03-04 because 2019-02-28 to 2019-03-03 were holidays in Taiwan.
  8. Ndc representative — Said a new checking mechanism was implemented and that the CN field is now generated by system rather than manually.
  9. Ndc representative — Said GRCA and its hierarchy would stop issuing TLS certificates after 2019-09-18 and that all TLS certificates would be revoked by 2020-07-19.
  10. Ndc representative — Confirmed that GRCA and its sub-CAs had not issued TLS certificates since 2019-09-18 and did not issue S/MIME certificates.
  11. Mozilla representative — Summarized the intended root changes, including distrust-after for TLS and removal of the Email trust bit.
  12. Ndc representative — Asked for more time and requested that the root certificate be removed after 2020-07-19.
  13. Mozilla representative — Closed the bug as resolved by removal of the root certificate from NSS.
Participants
Community commenter Fastly representative Ndc representative Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1390990 RESOLVED Certificate Misissuance Delayed Revocation Opened 2017-08-16 · Closed 2023-02-22 · 96% similar
D-TRUST: Non-BR-Compliant Certificate Issuance
#1390977 RESOLVED Certificate Misissuance Opened 2017-08-16 · Closed 2023-02-22 · 88% similar
Camerfirma: Non-BR-Compliant Certificate Issuance
#1390988 RESOLVED Ca Certificate Compliance Incident Externally Reported Incident Certificate Misissuance Opened 2017-08-16 · Closed 2023-02-22 · 86% similar
Consorci AOC: Non-BR-Compliant Certificate Issuance
#1590810 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-10-23 · Closed 2023-02-22 · 85% similar
Sectigo: EV SSL Certificates with incorrect businessCategory
#1502957 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2018-10-29 · Closed 2023-02-22 · 84% similar
Camerfirma: MULTICERT Misissuance and missing audits
#1502957 RESOLVED Certificate Misissuance Incident Opened 2018-10-29 · Closed 2023-02-22 · 84% similar
Camerfirma: MULTICERT Misissuance and missing audits
#1644936 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2020-06-11 · Closed 2024-05-09 · 83% similar
Microsoft PKI Services: Certificate Mis-Issuance, Locality Missing
#1391429 RESOLVED Certificate Misissuance Revocation Issue Opened 2017-08-17 · Closed 2024-02-27 · 79% similar
GoDaddy: Non-BR-Compliant Certificate Issuance

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action