GDCA: Incorrect Value in organizationName Field
GDCA reported that it discovered a mis-issued SSL/TLS certificate during its routine internal audit on 26 August 2020. The issue involved an incorrect value in the certificate’s organizationName field; GDCA stated that one EV SSL certificate was affected and was issued on 25 August 2020. After confirming the mis-issuance, GDCA started revocation procedures and revoked the affected certificate on 26 August 2020. GDCA also checked all currently valid SSL certificates it had issued and reported finding no other certificates with a similar issue. GDCA said it stopped issuance of certificates with similar problems immediately after confirming the mis-issuance. As mitigation, GDCA described revisiting its issuance procedures and developing a feature in its Certificate Management System to match organizationName, streetAddress, and SerialNumber values against a Qualified Government Information Source; it reported deploying this feature by 4 September 2020. GDCA notified its WebTrust auditor of the mis-issuance on 1 September 2020, and Mozilla indicated it would close the bug unless further issues or questions were raised. The bug is resolved as FIXED.
- GDCA identified a mis-issued EV SSL certificate during a routine internal audit and confirmed the mis-issuance.
- GDCA revoked the affected EV SSL certificate after confirming the mis-issuance.
- GDCA notified its WebTrust auditor about the mis-issuance.
- GDCA deployed a Certificate Management System feature to validate/match certificate field values against a Qualified Government Information Source.
- Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) — GDCA disclosed the incident, including its timeline, revocation, checks for other affected certificates, and a mitigation plan to add system matching for organizationName/streetAddress/SerialNumber.
- Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) — GDCA reported that it had deployed the mitigation feature in its Certificate Management System.
- Community commenter — Ryan Sleevi commented that the incident report was detailed and that there were no follow-up questions.
- Mozilla representative — Mozilla stated it would close the bug around 25 September 2020 unless other issues or questions were raised.