← Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) cases
Bugzilla #1536831 Ca Certificate Compliance Revocation Issue Remediation Tracking

GDCA: Insufficient Serial Number Entropy

RESOLVED FIXED Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA))
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns GDCA certificates with insufficient serial number entropy (serial number length less than 64 bits). GDCA said it became aware of the issue after noticing a discussion on mozilla.dev.security.policy about insufficient certificate serial numbers and then performing a self-assessment of the SSL/TLS certificates it issued. GDCA confirmed that certificates issued on or after December 1, 2017 by its upgraded issuance system exceeded 120 bits and were compliant, and it did not suspend current issuance. For certificates issued between September 30, 2016 and December 1, 2017, GDCA reported 283 affected SSL/TLS certificates, including 14 still valid with serial number length less than 64 bits. GDCA revoked 8 of the 14 valid certificates on March 19, 2019 and stated it expected to revoke the remaining 6 by March 31, 2019; it later reported that the additional 6 were revoked on March 29, 2019 and that all affected certificates were either revoked or expired as of that date. In response to questions about revocation delay, GDCA attributed the timing to customer revocation/replacement procedures for government institutions and said it would work to improve future efficiency while ensuring revocation meets BRs. The bug was resolved as FIXED, and a later comment indicated remediation was complete.

Model: gpt-5.4-nano Generated: 2026-06-13 18:09 UTC Revised: 2026-06-16 18:30 UTC Confidence: 0.86 6 comments
Chronology
  1. GDCA upgraded its certificate issuance system and configured EJBCA serial number octet size to 16 to ensure serial number length exceeds 64 bits.
  2. Certificates with serial number length less than 64 bits were issued during this period (as later identified by GDCA).
  3. GDCA noticed the mozilla.dev.security.policy discussion about insufficient certificate serial numbers and began reviewing its issuance system.
  4. GDCA revoked 8 of the 14 still-valid affected certificates with serial number length less than 64 bits.
  5. GDCA revoked the remaining 6 affected certificates; GDCA reported all affected certificates were revoked or expired.
  6. A participant stated remediation appeared complete.
Thread Activity
  1. Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) — GDCA described its self-assessment and actions, including confirming compliance for certificates issued after Dec 1, 2017, identifying 283 affected certificates from Sep 30, 2016 to Dec 1, 2017, revoking 8 valid certificates on Mar 19, 2019, and updating lint tools to prevent further issuance of serial numbers under 64 bits.
  2. Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) — GDCA reported it revoked the additional 6 affected certificates on March 29, 2019 and stated all affected certificates were revoked or expired as of that date.
  3. Community commenter — Ryan asked GDCA to explain the delay in revoking the additional 6 certificates and how future delays would be prevented.
  4. Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) — GDCA explained the delay as due to time-consuming customer revocation/replacement procedures (especially for government institutions) and said it would improve communication efficiency and execute mandatory revocation when necessary.
  5. Community commenter — Ryan asked whether any further descriptions of steps taken were needed and noted it should be watched for future incidents.
  6. Fastly representative — A participant stated it appeared all questions had been answered and remediation was complete.
Participants
Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) Community commenter Fastly representative
Similar Local Cases
#1520876 RESOLVED Ca Certificate Compliance Delayed Revocation Opened 2019-01-17 · Closed 2023-02-22 · 80% similar
Entrust: Late mis-issue certificate revocation
#1662382 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2020-09-01 · Closed 2023-02-22 · 79% similar
GDCA: Incorrect Value in organizationName Field
#1600158 RESOLVED Ca Certificate Compliance Delayed Revocation Opened 2019-11-28 · Closed 2023-02-22 · 79% similar
Asseco DS / Certum: Failure to revoke intermediate certificates within the BR time period
#1546253 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2019-04-23 · Closed 2023-02-22 · 78% similar
GDCA: Authentication of Organization Identity Failure for an OV Certificate
#1521520 RESOLVED Ca Certificate Compliance Delayed Revocation Opened 2019-01-21 · Closed 2023-02-22 · 75% similar
Entrust: Late revocation of underscore certificate
#1523680 RESOLVED Revocation Issue Incident Opened 2019-01-29 · Closed 2023-02-22 · 75% similar
Actalis: Non BR Compliant OCSP Responder
#1475563 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2018-07-13 · Closed 2022-11-14 · 74% similar
GDCA: Misissuance of certificates with IP address
#1391000 RESOLVED Ca Certificate Compliance Incident Revocation Issue Opened 2017-08-16 · Closed 2023-02-22 · 72% similar
IdenTrust: Non-BR-Compliant Certificate Issuance

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action