GDCA: CRL validity period exceeds allowed value by one second
The case concerns Global Digital Cybersecurity Authority Co., Ltd. (formerly Guang Dong Certificate Authority (GDCA)) reporting that its CRL validity periods exceeded the limits in Mozilla Baseline Requirements and its own CPS by one second. GDCA stated that it noticed the issue after other CAs reported similar CRL validity period problems on Bugzilla earlier in October 2021, and then confirmed that its own trusted root CRL and subscriber certificate CRLs were affected. GDCA reported that the root certificate CRL was issued on 15 July 2021 with a validity period of twelve months plus one second, which it said violated Baseline Requirements section 4.9.7, and that subscriber certificate CRLs were valid for 48 hours plus one second, which it said violated its CPS section 4.9.7. GDCA also stated it informed its WebTrust auditor of the issue and decided to re-issue the root certificate CRL with an appropriate validity period, and to revise its CPS wording for CRL validity. The bug’s resolution is listed as INVALID and the cached status is RESOLVED in the provided case data.
- GDCA issued the CRL for its trusted root certificate with a validity period of twelve months plus one second.
- GDCA confirmed its root and subscriber CRL validity periods violated Baseline Requirements and its CPS.
- GDCA informed its WebTrust auditor and decided to re-issue the root CRL and revise its CPS wording.
- Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) — GDCA described how it became aware of the CRL validity period issue, provided the specific one-second exceedance details for root and subscriber CRLs, and outlined planned remediation steps including re-issuing the root CRL and revising its CPS.