GRCA: Misissued certificates - invalid CN, bad validity period, missing extensions
The Government Root Certification Authority (GRCA) disclosed a misissuance incident involving certificates with an invalid common name, a validity period exceeding 825 days, and missing required extensions. The issue was identified by an external party, prompting GRCA to provide an incident report. GRCA clarified that the certificates in question were not intended for TLS use and expressed a willingness to include extended key usage (EKU) in future certificates. Following discussions, GRCA committed to including EKUs in all end-entity certificates issued after July 1, 2020, to comply with Mozilla's Root Store Policy. The bug was resolved with a plan for compliance.
- GRCA disclosed misissued certificates with compliance failures.
- GRCA confirmed plans to include EKUs in future certificates.
- Titanous representative — Reported misissued certificates by GRCA with invalid commonName and missing extensions.
- Ndc representative — GRCA explained the certificates are not used for TLS and requested they not be treated as misissued.
- Ndc representative — Submitted the incident report addressing the misissuance.
- Ndc representative — GRCA confirmed compliance with Mozilla's policy to include EKUs in future certificates.