← Government of Taiwan, Government Root Certification Authority (GRCA) cases
Bugzilla #1523221
Certificate Misissuance
GRCA: Misissued certificates - invalid CN, bad validity period, missing extensions
RESOLVED
FIXED
Government of Taiwan, Government Root Certification Authority (GRCA)
AI Summary
The Government Root Certification Authority (GRCA) issued certificates that contained an invalid common name, exceeded the maximum validity period, and lacked required extensions such as EKU and SAN. Although GRCA argued that these certificates were not intended for TLS use, Mozilla's policy classifies them as misissued due to the absence of necessary extensions. An incident report was provided, and GRCA committed to including EKUs in all end-entity certificates issued after July 1, 2020, to comply with Mozilla's Root Store Policy.
Chronology
- Bug created regarding misissued certificates.
- GRCA submitted an incident report.
- GRCA confirmed compliance plan for EKUs.
- Bug resolved as GRCA's remediation plan was accepted.
Participants
Jonathan Rudenberg
Wayne Thayer
gpki@ndc.gov.tw
External References
Similar Local Cases
GRCA: Misissued certificates: Invalid commonName, commonName not in SAN
Telia: Misissued certificate - invalid dnsName
SwissSign: Cert issued with a to long validity period
Microsec: Validity period greater than 825 days
FNMT: OU exceeds 64 characters
Firmaprofesional: Undisclosed Intermediate certificate
Camerfirma: Missing audit for Intermediate certificate
Camerfirma: MULTICERT Misissuance and missing audits