GDCA incident report: SSL/TLS certificates issued with non-critical Basic Constraints
GDCA reported that it issued 20 SSL/TLS certificates between 2023-09-15 and 2023-10-08 with the Basic Constraints extension present but not marked critical. The issue was first raised internally as a preliminary report on 2024-03-27 after GDCA received a third-party certificate problem report on 2024-03-26. GDCA said it began contacting affected customers to revoke and replace the certificates, and later stated that all affected certificates were either revoked or expired. The report also described the root cause as GDCA’s misunderstanding of the Basic Constraints criticality requirement in SC 62 v2, together with zlint in production not flagging the issue at the time. GDCA updated its action items to include revising its CP/CPS, improving Bugzilla incident monitoring and response, updating zlint, and deploying pkilint. In the closure summary, GDCA said all action items had been completed and requested closure.
- First affected SSL/TLS certificate was issued with Basic Constraints present but not marked critical.
- Last affected SSL/TLS certificate was issued with Basic Constraints present but not marked critical.
- GDCA received a third-party certificate problem report about the issue.
- GDCA confirmed the issue and published a preliminary incident report.
- GDCA submitted a closure summary and requested closure of the incident report.
- Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) — GDCA opened a preliminary report acknowledging issuance of SSL/TLS certificates with Basic Constraints not set as critical.
- Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) — GDCA filed an incident report stating that 20 certificates were affected and that some had expired or been revoked.
- Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) — GDCA said all affected certificates were revoked or expired and opened Bug 1889062 for delayed revocation.
- Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) — GDCA answered questions about Bugzilla monitoring, linting evaluation, and said it planned to add pkilint alongside zlint.
- Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) — GDCA said it would update its Bugzilla incident monitoring and response steps and listed revised action items.
- Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) — GDCA explained it changed its issuance system on 2023-10-08 after revisiting SC 62 v2 and researching how other CAs handled Basic Constraints.
- Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) — GDCA posted an updated action-item status showing several items completed and others in progress.
- Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) — GDCA reported that updating zlint was completed and pkilint deployment remained in progress.
- Mozilla representative — Mozilla requested a closure summary.
- Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) — GDCA submitted a closure summary stating the incident, root cause, remediation, and that all action items were completed.
- Mozilla representative — Mozilla said it would close the bug on 2025-03-05 unless there were questions or concerns.