GDCA: Authentication of Organization Identity Failure for an OV Certificate
GDCA reported a mis-issuance incident it discovered through its routine internal audit for Q1 2019. The CA stated that on 19 April 2019 it identified an OV certificate that had been mis-issued, with the certificate issued on 28 March 2019. GDCA said the mis-issuance occurred due to an operator error: a “test” was mistakenly added in the O field for a certificate intended for deployment on GDCA-hosted test websites, and the validation specialist did not detect the issue because the certificate was for GDCA’s own use. In response, GDCA stopped issuing certificates with similar problems immediately after confirming the mis-issuance, added “Test”, “测试”, and “Example” to its CMS Sensitive Data List to redirect future requests to its Compliance team, and began certificate revocation procedures. GDCA revoked the affected certificate on 22 April 2019 and notified its WebTrust auditor. The bug was later left open briefly by Mozilla’s reviewer and then marked as remediation complete, with the bug status resolved as FIXED.
- GDCA issued one OV SSL certificate that was later identified as mis-issued.
- GDCA identified the mis-issued certificate during its routine internal audit for Q1 2019.
- GDCA revoked the affected certificate and notified its WebTrust auditor.
- Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) — GDCA provided an incident report describing how it discovered the mis-issuance, the timeline, the affected certificate, and remediation steps including CMS Sensitive Data List updates, revocation, and retraining.
- Fastly representative — Mozilla’s reviewer said the report appeared to contain all required information and left the bug open in case of questions.
- Mozilla representative — The bug type was corrected to task.
- Fastly representative — The reviewer stated it appeared all questions were answered and remediation was complete.