← Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) cases
Bugzilla #1546253 Ca Certificate Compliance Certificate Misissuance Closure Request

GDCA: Authentication of Organization Identity Failure for an OV Certificate

RESOLVED FIXED Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA))
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

GDCA reported a mis-issuance incident it discovered through its routine internal audit for Q1 2019. The CA stated that on 19 April 2019 it identified an OV certificate that had been mis-issued, with the certificate issued on 28 March 2019. GDCA said the mis-issuance occurred due to an operator error: a “test” was mistakenly added in the O field for a certificate intended for deployment on GDCA-hosted test websites, and the validation specialist did not detect the issue because the certificate was for GDCA’s own use. In response, GDCA stopped issuing certificates with similar problems immediately after confirming the mis-issuance, added “Test”, “测试”, and “Example” to its CMS Sensitive Data List to redirect future requests to its Compliance team, and began certificate revocation procedures. GDCA revoked the affected certificate on 22 April 2019 and notified its WebTrust auditor. The bug was later left open briefly by Mozilla’s reviewer and then marked as remediation complete, with the bug status resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 18:11 UTC Revised: 2026-06-16 18:31 UTC Confidence: 0.90 5 comments
Chronology
  1. GDCA issued one OV SSL certificate that was later identified as mis-issued.
  2. GDCA identified the mis-issued certificate during its routine internal audit for Q1 2019.
  3. GDCA revoked the affected certificate and notified its WebTrust auditor.
Thread Activity
  1. Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) — GDCA provided an incident report describing how it discovered the mis-issuance, the timeline, the affected certificate, and remediation steps including CMS Sensitive Data List updates, revocation, and retraining.
  2. Fastly representative — Mozilla’s reviewer said the report appeared to contain all required information and left the bug open in case of questions.
  3. Mozilla representative — The bug type was corrected to task.
  4. Fastly representative — The reviewer stated it appeared all questions were answered and remediation was complete.
Participants
Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) Fastly representative Mozilla representative
External References
Similar Local Cases
#1662382 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2020-09-01 · Closed 2023-02-22 · 100% similar
GDCA: Incorrect Value in organizationName Field
#1738183 RESOLVED Self Reported Incident Certificate Misissuance Opened 2021-10-28 · Closed 2022-11-14 · 88% similar
GDCA: CRL validity period exceeds allowed value by one second
#1888060 RESOLVED Self Reported Incident Certificate Misissuance Opened 2024-03-27 · Closed 2025-03-05 · 88% similar
GDCA: Issuance of SSL/TLS certificates with Non-critical Basic Constraints
#1467414 RESOLVED Certificate Misissuance Self Reported Incident Opened 2018-06-07 · Closed 2023-02-22 · 85% similar
GDCA: Misissuance of certificates with small RSA keys
#1475563 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2018-07-13 · Closed 2022-11-14 · 85% similar
GDCA: Misissuance of certificates with IP address
#1559765 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-06-17 · Closed 2023-02-22 · 81% similar
Izenpe: Multiple invalid EV certificates issued
#1528261 RESOLVED Certificate Misissuance Opened 2019-02-15 · Closed 2023-02-22 · 79% similar
Telia: Misissued certificate - FQDN without domain part (e_dnsname_not_valid_tld)
#1532436 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2019-03-04 · Closed 2023-02-22 · 79% similar
Chunghwa Telecom: Test certificate with unregistered domain name

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action