← Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) cases
Bugzilla #1467414 Certificate Misissuance Self Reported Incident

GDCA: Misissuance of certificates with small RSA keys

RESOLVED FIXED Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA))
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Global Digital Cybersecurity Authority Co., Ltd. (GDCA) disclosed a misissuance incident involving seven certificates issued with RSA-1024 keys, which violate the CA/Browser Forum Baseline Requirements. The issue was reported by Rob Stradling on June 7, 2018, prompting GDCA to investigate. They suspended DV SSL certificate issuance, confirmed the mis-issuance, and revoked the affected certificates on the same day. GDCA identified a bug in their certificate issuance system that led to the misconfiguration of RSA key size checks. They have since implemented corrective measures, including integrating linting tools to prevent future occurrences. The DV SSL certificate issuance service was resumed on June 27, 2018, with pre-issuance checks now in place.

Model: gpt-4o-mini Generated: 2026-06-13 17:51 UTC Revised: 2026-06-16 18:29 UTC Confidence: 0.90 15 comments
Chronology
  1. GDCA issued certificates with RSA-1024 keys, violating Baseline Requirements.
  2. GDCA resumed DV SSL certificate issuance with pre-issuance linting enabled.
Thread Activity
  1. Sectigo — Reported misissuance of certificates with RSA-1024 keys.
  2. Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) — Acknowledged the issue and began handling it.
  3. Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) — Provided initial report detailing the investigation and actions taken.
  4. Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) — Confirmed resumption of DV SSL certificate issuance with new checks in place.
Participants
Sectigo Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) Community commenter Fastly representative
External References
Similar Local Cases
#1532559 RESOLVED Certificate Misissuance Self Reported Incident Opened 2019-03-05 · Closed 2023-02-22 · 90% similar
CFCA: Wrong SerialNumber encoding
#1738183 RESOLVED Self Reported Incident Certificate Misissuance Opened 2021-10-28 · Closed 2022-11-14 · 89% similar
GDCA: CRL validity period exceeds allowed value by one second
#1599484 RESOLVED Self Reported Incident Certificate Misissuance Opened 2019-11-26 · Closed 2023-02-22 · 89% similar
Entrust: EV Certificates Issued with Business Category "Non-Commercial" when it should have been set to "Private Organization"
#1409766 RESOLVED Ca Certificate Compliance Self Reported Incident Certificate Misissuance Opened 2017-10-18 · Closed 2023-02-22 · 89% similar
Asseco DS / Certum: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record
#1506607 RESOLVED Self Reported Incident Certificate Misissuance Opened 2018-11-12 · Closed 2026-06-10 · 88% similar
SwissSign: Misissuance of Intermediate Certificates because of incorrect organizationIdentifier
#1556806 RESOLVED Certificate Misissuance Self Reported Incident Opened 2019-06-04 · Closed 2023-02-22 · 88% similar
Camerfirma: Infocert misissued certificates
#1534429 RESOLVED Ca Certificate Compliance Self Reported Incident Incident Certificate Misissuance Opened 2019-03-11 · Closed 2023-02-22 · 87% similar
Camerfirma: Multicert SSL CA 001: Insufficient serial number entropy
#1552586 RESOLVED Self Reported Incident Certificate Misissuance Opened 2019-05-17 · Closed 2023-02-22 · 87% similar
GlobalSign: 4 Misissued certificates with invalid CN

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action