← Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) cases
Bugzilla #1662382 Ca Certificate Compliance Certificate Misissuance Closure Request

GDCA: Incorrect Value in organizationName Field

RESOLVED FIXED Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA))
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

GDCA reported that it discovered a mis-issued SSL/TLS certificate during its routine internal audit on 26 August 2020. The issue involved an incorrect value in the certificate’s organizationName field; GDCA stated that one EV SSL certificate was affected and was issued on 25 August 2020. After confirming the mis-issuance, GDCA started revocation procedures and revoked the affected certificate on 26 August 2020. GDCA also checked all currently valid SSL certificates it had issued and reported finding no other certificates with a similar issue. GDCA said it stopped issuance of certificates with similar problems immediately after confirming the mis-issuance. As mitigation, GDCA described revisiting its issuance procedures and developing a feature in its Certificate Management System to match organizationName, streetAddress, and SerialNumber values against a Qualified Government Information Source; it reported deploying this feature by 4 September 2020. GDCA notified its WebTrust auditor of the mis-issuance on 1 September 2020, and Mozilla indicated it would close the bug unless further issues or questions were raised. The bug is resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:20 UTC Revised: 2026-06-16 18:32 UTC Confidence: 0.90 4 comments
Chronology
  1. GDCA identified a mis-issued EV SSL certificate during a routine internal audit and confirmed the mis-issuance.
  2. GDCA revoked the affected EV SSL certificate after confirming the mis-issuance.
  3. GDCA notified its WebTrust auditor about the mis-issuance.
  4. GDCA deployed a Certificate Management System feature to validate/match certificate field values against a Qualified Government Information Source.
Thread Activity
  1. Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) — GDCA disclosed the incident, including its timeline, revocation, checks for other affected certificates, and a mitigation plan to add system matching for organizationName/streetAddress/SerialNumber.
  2. Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) — GDCA reported that it had deployed the mitigation feature in its Certificate Management System.
  3. Community commenter — Ryan Sleevi commented that the incident report was detailed and that there were no follow-up questions.
  4. Mozilla representative — Mozilla stated it would close the bug around 25 September 2020 unless other issues or questions were raised.
Participants
Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) Community commenter Mozilla representative
External References
Similar Local Cases
#1546253 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2019-04-23 · Closed 2023-02-22 · 100% similar
GDCA: Authentication of Organization Identity Failure for an OV Certificate
#1738183 RESOLVED Self Reported Incident Certificate Misissuance Opened 2021-10-28 · Closed 2022-11-14 · 97% similar
GDCA: CRL validity period exceeds allowed value by one second
#1888060 RESOLVED Self Reported Incident Certificate Misissuance Opened 2024-03-27 · Closed 2025-03-05 · 95% similar
GDCA: Issuance of SSL/TLS certificates with Non-critical Basic Constraints
#1740493 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-11-10 · Closed 2023-02-22 · 88% similar
Sectigo: Failure to block disallowed LDH labels in domain names
#1672423 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2020-10-21 · Closed 2023-02-22 · 87% similar
Camerfirma: certificate for unregistered domain cuatis.net
#1559765 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-06-17 · Closed 2023-02-22 · 87% similar
Izenpe: Multiple invalid EV certificates issued
#1711432 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-05-17 · Closed 2023-02-22 · 86% similar
Telekom Security: Certificate with invalid FQDN
#1575022 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2019-08-19 · Closed 2023-02-22 · 86% similar
Sectigo: EV SSL Certificates with incorrect subject details.

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action