← Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) cases
Bugzilla #1738191 Technical Compliance

GDCA: CRL validity period exceeds allowed value by one second

RESOLVED FIXED Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA))
AI Summary

The Global Digital Cybersecurity Authority (GDCA) identified a compliance issue regarding the validity period of their Certificate Revocation Lists (CRLs). The CRL for their trusted root certificate exceeded the allowed validity period by one second, violating Baseline Requirements. GDCA took immediate action by re-issuing the CRL with a corrected validity period and updating their Certificate Policy/Certificate Practice Statement (CP/CPS) to prevent future occurrences. The issue did not result in certificate mis-issuance, and GDCA has continued certificate issuance throughout the resolution process.

Model: gpt-4o-mini Generated: 2026-06-13 21:21 UTC Confidence: 1.00
Chronology
  1. Issued the CRL for the Root certificate
  2. Noticed CRL issues reported by several CAs on Bugzilla
  3. Confirmed CRL validity period violations
  4. Informed WebTrust auditor and decided to re-issue the CRL
  5. Re-issued and published the root CRL with updated validity period
  6. Updated CP/CPS regarding CRL issuance frequency
Participants
capoc@gdca.com.cn bwilson@mozilla.com
Similar Local Cases
#1732745 RESOLVED Technical Compliance Opened 2021-09-27 · Closed 2023-02-22 · 53% similar
Certainly: Root CRL validity period exceeds maximum by one second
#1848280 RESOLVED Technical Compliance Opened 2023-08-11 · Closed 2023-10-12 · 50% similar
Microsoft PKI Services: 3-Month Access Review Process Failure
#1772644 RESOLVED Technical Compliance Opened 2022-06-04 · Closed 2023-02-22 · 50% similar
Apple: CRL issuance frequency deviates from CPS in some cases
#1848279 RESOLVED Technical Compliance Opened 2023-08-11 · Closed 2023-10-12 · 47% similar
Microsoft PKI Services: Trusted Role Control Failure
#1914893 RESOLVED Technical Compliance Opened 2024-08-26 · Closed 2024-09-18 · 47% similar
Amazon Trust Services: CRL not DER-encoded
#1793441 RESOLVED Technical Compliance Opened 2022-10-03 · Closed 2023-02-22 · 46% similar
GlobalSign: CRL contains invalid signature algorithm
#1735761 RESOLVED Technical Compliance Opened 2021-10-14 · Closed 2023-02-22 · 46% similar
Sectigo: CRL validity beyond CPS allowed value
#1737057 RESOLVED Technical Compliance Opened 2021-10-21 · Closed 2023-02-22 · 44% similar
Entrust: CRLs and OCSP responses not issued as specified in the CPS

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action