GDCA: CRL validity period exceeds allowed value by one second
GDCA reported that its CRLs had a validity period that exceeded the allowed value by one second. The CA said it noticed the issue after other CAs reported similar CRL validity problems on Bugzilla, and it confirmed that its trusted root certificate CRL was issued with a validity period of twelve months plus one second, which it stated violates Baseline Requirements section 4.9.7. GDCA also stated that subscriber certificate CRLs were valid for 48 hours plus one second, which it said violated its CPS section 4.9.7, and it checked OCSP response validity as well. In response, GDCA informed its WebTrust auditor and decided to re-issue the root CRL with an appropriate validity period, and to revise its CPS wording for CRL issuance frequency and the nextUpdate field. The CA reported re-issuing and publishing the root CRL, and later updated its CP/CPS on November 1, pointing to changes in sections 2.3 and 4.9.7 related to CRL issuance frequency. Mozilla indicated it would close the bug on or about November 4, 2021 unless there were additional questions, and the bug is marked RESOLVED with resolution FIXED.
- GDCA issued the CRL for its trusted root certificate with a validity period of twelve months plus one second.
- GDCA confirmed that its root and subscriber CRL validity periods violated the Baseline Requirements and its CPS, respectively.
- GDCA informed its WebTrust auditor and decided to re-issue the root CRL and revise its CPS wording.
- GDCA re-issued and published the root CRL with an updated validity period.
- GDCA updated its CP/CPS to revise CRL issuance frequency and nextUpdate constraints.
- Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) — GDCA described how it became aware of the CRL validity period issue and provided a timeline and stated compliance violations for root and subscriber CRLs.
- Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) — GDCA reported that it re-issued and published the root CRL and provided the updated validity period.
- Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) — GDCA stated it updated its CP/CPS on November 1 and believed the proposed remediation steps were completed.
- Mozilla representative — Mozilla said it would close the bug on or about Thursday, 4-Nov-2021 unless there were additional questions or concerns.