GDCA: Misissuance of certificates with small RSA keys
Global Digital Cybersecurity Authority Co., Ltd. (GDCA) disclosed a misissuance incident involving seven certificates issued with RSA-1024 keys, which violate the CA/Browser Forum Baseline Requirements. The issue was reported by Rob Stradling on June 7, 2018, prompting GDCA to investigate. They suspended DV SSL certificate issuance, confirmed the mis-issuance, and revoked the affected certificates on the same day. GDCA identified a bug in their certificate issuance system that led to the misconfiguration of RSA key size checks. They have since implemented corrective measures, including integrating linting tools to prevent future occurrences. The DV SSL certificate issuance service was resumed on June 27, 2018, with pre-issuance checks now in place.
- GDCA issued certificates with RSA-1024 keys, violating Baseline Requirements.
- GDCA resumed DV SSL certificate issuance with pre-issuance linting enabled.
- Sectigo — Reported misissuance of certificates with RSA-1024 keys.
- Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) — Acknowledged the issue and began handling it.
- Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) — Provided initial report detailing the investigation and actions taken.
- Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) — Confirmed resumption of DV SSL certificate issuance with new checks in place.