← Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) cases
Bugzilla #1536831
Certificate Problem Report
GDCA: Insufficient Serial Number Entropy
RESOLVED
FIXED
Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA))
AI Summary
Global Digital Cybersecurity Authority (GDCA) identified an issue with insufficient serial number entropy in SSL/TLS certificates issued between September 30, 2016, and December 1, 2017. Following discussions on mozilla.dev.security.policy, GDCA conducted a self-assessment and confirmed that 283 certificates were affected. They successfully revoked 14 valid certificates and updated their issuance system to prevent future occurrences. The issue has been resolved, and all affected certificates are now either revoked or expired.
Chronology
- GDCA noticed discussions about insufficient serial number entropy.
- GDCA confirmed issuance of 283 affected certificates.
- GDCA began revocation procedures for affected certificates.
- GDCA completed revocation of all affected certificates.
Participants
capoc@gdca.com.cn
ryan.sleevi@gmail.com
wthayer@fastly.com
Similar Local Cases
Atos: Insufficient Serial Number Entropy
Firmaprofesional: AC Firmaprofesional - INFRAESTRUCTURA insufficient serial number entropy
Camerfirma: Multicert SSL CA 001: Insufficient serial number entropy
Camerfirma: Multicert SSL CA 001: Insufficient serial number entropy
D-TRUST: Issuance of non-conformant SSL certificate
GlobalSign: SPKI lacks explicit NULL parameter,
SSL.com: Precertificates without corresponding certificates return OCSP value of "Unknown"
GlobalSign: OCSP Responder Returns invalid values for Some Precertificates