← Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) cases
Bugzilla #1475563 Ca Certificate Compliance Certificate Misissuance Closure Request

GDCA: Misissuance of certificates with IP address

INVALID INVALID Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA))
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The bug was raised by an external reporter alleging that Global Digital Cybersecurity Authority Co., Ltd. (formerly GDCA) issued certificates for IP addresses with insufficient authorization. The reporter pointed to examples on crt.sh and argued that the CA’s IP address validation did not meet the Baseline Requirements. The CA responded that it validated IP addresses according to Section 3.2.2.5 of the CA/B Forum Baseline Requirements and that it rejected requests for reserved IP addresses as required, and it stated that it switched IP address certificate request and validation to a manual mode as a best-practice change. The Mozilla CA Program reviewer asked for more specific information about the alleged violation and noted that Section 3.2.2.5 allows file-based authorization via an agreed-upon change to an online web page identified by a URI containing the IP address. After receiving no further evidence of misissuance, the reviewer concluded the report was a false alarm and marked the bug as INVALID.

Model: gpt-5.4-nano Generated: 2026-06-13 17:52 UTC Revised: 2026-06-16 18:29 UTC Confidence: 0.86 4 comments
Chronology
  1. An external reporter filed a complaint alleging GDCA misissued IP address certificates.
  2. GDCA replied that its IP validation followed Baseline Requirements and stated it moved to manual validation.
  3. The reviewer concluded the report was a false alarm and closed the case as INVALID.
Thread Activity
  1. Community commenter — Reported that many IP address certificates issued by GDCA appear on crt.sh and argued the CA violated BR due to insufficient authorization.
  2. Fastly representative — Asked for specific details about the alleged BR violation and cited Baseline Requirements section 3.2.2.5 as allowing file-based authorization.
  3. Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) — Stated GDCA validated IP addresses per BR 3.2.2.5, rejected reserved IP requests, and switched IP certificate request/validation to manual mode.
  4. Fastly representative — Concluded that, with no further evidence of misissuance, the report was a false alarm.
Participants
Community commenter Fastly representative Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA))
Similar Local Cases
#1546253 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2019-04-23 · Closed 2023-02-22 · 85% similar
GDCA: Authentication of Organization Identity Failure for an OV Certificate
#1521623 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-01-21 · Closed 2024-05-09 · 77% similar
Amazon Trust Services: Failure to comply with RFC 5280
#1662382 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2020-09-01 · Closed 2023-02-22 · 76% similar
GDCA: Incorrect Value in organizationName Field
#1536831 RESOLVED Ca Certificate Compliance Revocation Issue Remediation Tracking Opened 2019-03-20 · Closed 2023-02-22 · 74% similar
GDCA: Insufficient Serial Number Entropy
#1398428 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-09-09 · Closed 2023-02-22 · 71% similar
Amazon Trust Services: CAA Misissuances
#1675923 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2020-11-07 · Closed 2024-05-09 · 70% similar
DigiCert: TERENA: Insufficient validation of organizationalUnitName
#1759122 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-03-11 · Closed 2022-11-14 · 70% similar
DigiCert: EV for Onion addresses without Tor Service Descriptor
#1942130 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2025-01-16 · Closed 2025-05-01 · 70% similar
HARICA: S/MIME certificate issuance without proper validation

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action