← Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) cases
Bugzilla #1738183 Self Reported Incident Certificate Misissuance

GDCA: CRL validity period exceeds allowed value by one second

RESOLVED INVALID Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA))
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The case concerns Global Digital Cybersecurity Authority Co., Ltd. (formerly Guang Dong Certificate Authority (GDCA)) reporting that its CRL validity periods exceeded the limits in Mozilla Baseline Requirements and its own CPS by one second. GDCA stated that it noticed the issue after other CAs reported similar CRL validity period problems on Bugzilla earlier in October 2021, and then confirmed that its own trusted root CRL and subscriber certificate CRLs were affected. GDCA reported that the root certificate CRL was issued on 15 July 2021 with a validity period of twelve months plus one second, which it said violated Baseline Requirements section 4.9.7, and that subscriber certificate CRLs were valid for 48 hours plus one second, which it said violated its CPS section 4.9.7. GDCA also stated it informed its WebTrust auditor of the issue and decided to re-issue the root certificate CRL with an appropriate validity period, and to revise its CPS wording for CRL validity. The bug’s resolution is listed as INVALID and the cached status is RESOLVED in the provided case data.

Model: gpt-5.4-nano Generated: 2026-06-13 21:21 UTC Revised: 2026-06-16 18:33 UTC Confidence: 0.86 2 comments
Chronology
  1. GDCA issued the CRL for its trusted root certificate with a validity period of twelve months plus one second.
  2. GDCA confirmed its root and subscriber CRL validity periods violated Baseline Requirements and its CPS.
  3. GDCA informed its WebTrust auditor and decided to re-issue the root CRL and revise its CPS wording.
Thread Activity
  1. Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) — GDCA described how it became aware of the CRL validity period issue, provided the specific one-second exceedance details for root and subscriber CRLs, and outlined planned remediation steps including re-issuing the root CRL and revising its CPS.
Participants
Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) Mozilla representative
External References
Similar Local Cases
#1888060 RESOLVED Self Reported Incident Certificate Misissuance Opened 2024-03-27 · Closed 2025-03-05 · 100% similar
GDCA: Issuance of SSL/TLS certificates with Non-critical Basic Constraints
#1662382 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2020-09-01 · Closed 2023-02-22 · 97% similar
GDCA: Incorrect Value in organizationName Field
#1467414 RESOLVED Certificate Misissuance Self Reported Incident Opened 2018-06-07 · Closed 2023-02-22 · 89% similar
GDCA: Misissuance of certificates with small RSA keys
#1546253 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2019-04-23 · Closed 2023-02-22 · 88% similar
GDCA: Authentication of Organization Identity Failure for an OV Certificate
#1910195 RESOLVED Certificate Misissuance Self Reported Incident Opened 2024-07-26 · Closed 2024-09-06 · 78% similar
IdenTrust: Invalid special characters in S/MIME Certificates
#1766255 RESOLVED Certificate Misissuance Self Reported Incident Opened 2022-04-25 · Closed 2023-02-22 · 78% similar
SwissSign: Mis-Issuance of S/MIME certificates
#1908130 RESOLVED Self Reported Incident Certificate Misissuance Opened 2024-07-16 · Closed 2024-08-28 · 78% similar
NAVER Cloud Trust Services: Incorrect keyUsage for ECC certificate
#1699796 RESOLVED Self Reported Incident Certificate Misissuance Opened 2021-03-19 · Closed 2023-02-22 · 77% similar
HARICA: Certificates with invalid policy tree

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action