← Government of Taiwan, Government Root Certification Authority (GRCA) cases
Bugzilla #1523221 Ca Certificate Compliance

GRCA: Misissued certificates - invalid CN, bad validity period, missing extensions

RESOLVED FIXED Government of Taiwan, Government Root Certification Authority (GRCA)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The Government Root Certification Authority (GRCA) disclosed a misissuance incident involving certificates with an invalid common name, a validity period exceeding 825 days, and missing required extensions. The issue was identified by an external party, prompting GRCA to provide an incident report. GRCA clarified that the certificates in question were not intended for TLS use and expressed a willingness to include extended key usage (EKU) in future certificates. Following discussions, GRCA committed to including EKUs in all end-entity certificates issued after July 1, 2020, to comply with Mozilla's Root Store Policy. The bug was resolved with a plan for compliance.

Model: gpt-4o-mini Generated: 2026-06-13 17:59 UTC Revised: 2026-06-16 19:10 UTC Confidence: 0.85 18 comments
Chronology
  1. GRCA disclosed misissued certificates with compliance failures.
  2. GRCA confirmed plans to include EKUs in future certificates.
Thread Activity
  1. Titanous representative — Reported misissued certificates by GRCA with invalid commonName and missing extensions.
  2. Ndc representative — GRCA explained the certificates are not used for TLS and requested they not be treated as misissued.
  3. Ndc representative — Submitted the incident report addressing the misissuance.
  4. Ndc representative — GRCA confirmed compliance with Mozilla's policy to include EKUs in future certificates.
Participants
Titanous representative Fastly representative Ndc representative
External References
Similar Local Cases
#1391056 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2017-08-16 · Closed 2023-02-22 · 77% similar
NetLock: Non-BR-Compliant Certificate Issuance
#1523186 RESOLVED Ca Certificate Compliance Opened 2019-01-27 · Closed 2023-02-22 · 71% similar
KIR S.A.: Misissuance - missing OCSP AIA, Validity > 825 days
#1618256 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-02-26 · Closed 2023-02-22 · 69% similar
DigiCert: Failure to properly encode Subject name
#1559765 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-06-17 · Closed 2023-02-22 · 69% similar
Izenpe: Multiple invalid EV certificates issued
#1586860 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-10-07 · Closed 2023-02-22 · 69% similar
Camerfirma: Invalid authorityKeyIdentifier, violating Mozilla Policy and RFC 5280
#1391066 RESOLVED Ca Certificate Compliance Opened 2017-08-16 · Closed 2023-02-22 · 68% similar
SwissSign: Non-BR-Compliant Certificate Issuance
#1390997 RESOLVED Ca Certificate Compliance Incident Revocation Issue Opened 2017-08-16 · Closed 2023-02-22 · 68% similar
GlobalSign: Non-BR-Compliant Certificate Issuance - metadata-only subject fields
#1398247 RESOLVED Ca Certificate Compliance Opened 2017-09-08 · Closed 2023-02-22 · 68% similar
DocuSign/Keynectis: Non-BR-Compliant OCSP Responders

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action