GDCA: Misissuance of certificates with IP address
The bug was raised by an external reporter alleging that Global Digital Cybersecurity Authority Co., Ltd. (formerly GDCA) issued certificates for IP addresses with insufficient authorization. The reporter pointed to examples on crt.sh and argued that the CA’s IP address validation did not meet the Baseline Requirements. The CA responded that it validated IP addresses according to Section 3.2.2.5 of the CA/B Forum Baseline Requirements and that it rejected requests for reserved IP addresses as required, and it stated that it switched IP address certificate request and validation to a manual mode as a best-practice change. The Mozilla CA Program reviewer asked for more specific information about the alleged violation and noted that Section 3.2.2.5 allows file-based authorization via an agreed-upon change to an online web page identified by a URI containing the IP address. After receiving no further evidence of misissuance, the reviewer concluded the report was a false alarm and marked the bug as INVALID.
- An external reporter filed a complaint alleging GDCA misissued IP address certificates.
- GDCA replied that its IP validation followed Baseline Requirements and stated it moved to manual validation.
- The reviewer concluded the report was a false alarm and closed the case as INVALID.
- Community commenter — Reported that many IP address certificates issued by GDCA appear on crt.sh and argued the CA violated BR due to insufficient authorization.
- Fastly representative — Asked for specific details about the alleged BR violation and cited Baseline Requirements section 3.2.2.5 as allowing file-based authorization.
- Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) — Stated GDCA validated IP addresses per BR 3.2.2.5, rejected reserved IP requests, and switched IP certificate request/validation to manual mode.
- Fastly representative — Concluded that, with no further evidence of misissuance, the report was a false alarm.