← Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) cases
Bugzilla #1738183 Certificate Problem Report

GDCA: CRL validity period exceeds allowed value by one second

RESOLVED INVALID Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA))
AI Summary

Global Digital Cybersecurity Authority Co., Ltd. (formerly GDCA) identified a compliance issue where the validity period of their Certificate Revocation List (CRL) exceeded the allowed duration by one second. This was discovered after noticing similar reports from other CAs. The CRL for their trusted root certificate was issued with a validity period of twelve months plus one second, violating Baseline Requirements. The CA has not halted certificate issuance as the issue does not lead to certificate mis-issuance. They have taken steps to re-issue the CRL with a compliant validity period and revise their Certificate Policy accordingly.

Model: gpt-4o-mini Generated: 2026-06-13 21:21 UTC Confidence: 0.90
Chronology
  1. Issued the CRL for the Root certificate
  2. Noticed CRL issues reported by several CAs on Bugzilla
  3. Confirmed CRL validity period violations
  4. Informed WebTrust auditor and decided to re-issue the CRL
Participants
capoc@gdca.com.cn bwilson@mozilla.com
External References
Similar Local Cases
#1843676 RESOLVED Certificate Problem Report Opened 2023-07-15 · Closed 2023-09-22 · 50% similar
Apple: Revocation Delay for TLS certificates issued outside the TTL of the CAA record
#1738207 RESOLVED Certificate Problem Report Opened 2021-10-28 · Closed 2023-02-22 · 49% similar
Telia: Issued three precertificates with non-NIST EC curve
#1536831 RESOLVED Certificate Problem Report Opened 2019-03-20 · Closed 2023-02-22 · 49% similar
GDCA: Insufficient Serial Number Entropy
#1666872 RESOLVED Certificate Problem Report Opened 2020-09-23 · Closed 2023-02-22 · 48% similar
SSL.com: Insufficient validation evidence for the localityName attribute of an OV certificate
#1790693 RESOLVED Certificate Problem Report Opened 2022-09-13 · Closed 2023-03-24 · 48% similar
SSL.com: Issuance of 1 EV TLS certificate using a Registration/Incorporation Agency not included in our approved public list.
#1637093 RESOLVED Certificate Problem Report Opened 2020-05-11 · Closed 2023-02-22 · 48% similar
Multicert: AIA CA Issuer field pointing to PEM encoded cert
#1944436 RESOLVED Certificate Problem Report Opened 2025-01-28 · Closed 2025-04-03 · 48% similar
Microsoft PKI Services: Subject Key Identifiers in Some Subscriber Certificates Do Not Comply with RFC 5280
#1841534 RESOLVED Certificate Problem Report Opened 2023-07-03 · Closed 2023-08-30 · 48% similar
Apple: TLS certificates issued outside the TTL of the CAA record

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action