← Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) cases
Bugzilla #1662382 Certificate Misissuance

GDCA: Incorrect Value in organizationName Field

RESOLVED FIXED Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA))
AI Summary

Global Digital Cybersecurity Authority (GDCA) identified a mis-issued EV SSL certificate during a routine internal audit on August 26, 2020. The certificate, issued on August 25, contained an incorrect value in the organizationName field. GDCA promptly revoked the certificate and implemented a new feature in their Certificate Management System to enhance validation procedures. This feature matches certificate data against a Qualified Government Information Source to prevent similar issues in the future. The incident was resolved with no further mis-issuances found.

Model: gpt-4o-mini Generated: 2026-06-13 21:20 UTC Confidence: 1.00
Chronology
  1. Certificate issued
  2. Mis-issuance identified
  3. Certificate revoked
  4. Notified WebTrust auditor
  5. New validation feature deployed
Participants
capoc@gdca.com.cn ryan.sleevi@gmail.com bwilson@mozilla.com
External References
Similar Local Cases
#1711432 RESOLVED Certificate Misissuance Opened 2021-05-17 · Closed 2023-02-22 · 60% similar
Telekom Security: Certificate with invalid FQDN
#1888060 RESOLVED Certificate Misissuance Opened 2024-03-27 · Closed 2025-03-05 · 58% similar
GDCA: Issuance of SSL/TLS certificates with Non-critical Basic Constraints
#1546253 RESOLVED Certificate Misissuance Opened 2019-04-23 · Closed 2023-02-22 · 58% similar
GDCA: Authentication of Organization Identity Failure for an OV Certificate
#1674886 RESOLVED Certificate Misissuance Opened 2020-11-02 · Closed 2023-02-22 · 57% similar
certSIGN: misissued an OV SSL certificate with no organizationName and localityName, instead of a DV SSL as requested by client
#1736064 RESOLVED Certificate Misissuance Opened 2021-10-15 · Closed 2023-02-22 · 57% similar
Sectigo: Subject field with unvalidated information included in certificates
#1724520 RESOLVED Certificate Misissuance Opened 2021-08-06 · Closed 2023-02-22 · 57% similar
SSL.com: Incorrect Domain Validation for 1 TLS certificate with FQDN having "www." string within domain labels
#1678720 RESOLVED Certificate Misissuance Opened 2020-11-20 · Closed 2023-02-22 · 56% similar
SSL.com: Wildcard DV certificate issued with a non-validated domain name
#1623356 RESOLVED Certificate Misissuance Opened 2020-03-18 · Closed 2023-02-22 · 55% similar
GlobalSign: Misissuance of QWAC Certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action