← Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) cases
Bugzilla #1889062 Delayed Revocation

GDCA delayed revocation of SSL/TLS certificates with non-critical Basic Constraints

RESOLVED FIXED Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA))
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

GDCA reported that it had issued 20 SSL/TLS certificates with the Basic Constraints extension present but not marked critical, and that 13 of those certificates were not revoked within the 5-day Baseline Requirements deadline after the issue was confirmed. The case was triggered by a certificate problem report received from a third party on 2024-03-26, after which GDCA confirmed the issue, opened a preliminary incident report, and began contacting affected customers. GDCA said all affected certificates were either revoked or expired by 2024-04-02, and it later provided an updated incident report, per-subscriber rationale, and a closure summary. Mozilla asked for clearer root-cause analysis, per-subscriber explanations, and stronger remediation tied to preventing future delayed revocation. GDCA described remediation steps including a rapid revocation response team, revised subscriber agreement language, emergency contact collection, revocation drills, and linting improvements, and Mozilla indicated the bug would remain open until those requirements were satisfied before closure.

Model: gpt-5.4-mini Generated: 2026-06-13 21:23 UTC Revised: 2026-06-16 18:37 UTC Confidence: 0.98 43 comments
Chronology
  1. First problematic SSL/TLS certificate was issued with Basic Constraints not set as critical.
  2. Last problematic SSL/TLS certificate was issued.
  3. A third party reported the certificate problem to GDCA.
  4. GDCA confirmed the issue and published a preliminary incident report.
  5. GDCA completed revocation of all problematic certificates.
  6. GDCA posted an incident closure summary and requested closure.
Thread Activity
  1. Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) — GDCA opened a preliminary incident report stating that 13 certificates had not been revoked within 5 days of receiving the certificate problem report.
  2. Mozilla representative — Mozilla asked whether full remediation had occurred and requested more concrete lessons learned about customer communication.
  3. Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) — GDCA said it had optimized its communication strategy and updated its internal approval process for certificate replacement.
  4. Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) — GDCA said it would increase customer support resources and provide 7x24 technical support during certificate replacement.
  5. Mozilla representative — Mozilla said the bug would remain open until GDCA provided a clear commitment to improve its treatment of revocations and an updated incident report.
  6. Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) — GDCA posted an updated incident report with revised root-cause analysis and additional remediation items.
  7. Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) — GDCA provided a per-subscriber rationale attachment and said it had not consulted its auditor about the revocation-delay risk analysis before the 5-day window expired.
  8. Mozilla representative — Mozilla said the bug would remain open until at least 2025-02-01 while incident-reporting and compliance work continued.
  9. Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) — GDCA filed an incident closure summary stating that all listed action items had been completed and requesting closure.
  10. Mozilla representative — Mozilla said it intended to close the bug on 2025-04-02 unless there were further questions or issues.
Participants
Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) Mozilla representative Community commenter Sectigo
Related Bugzilla IDs Mentioned
Similar Local Cases
#1877388 RESOLVED Delayed Revocation Incident Self Reported Incident Opened 2024-01-30 · Closed 2025-03-14 · 90% similar
Telekom Security: Revocation delay for TLS certificates with basicConstraints not marked as critical
#1886665 RESOLVED Delayed Revocation Opened 2024-03-21 · Closed 2025-02-28 · 89% similar
Hongkong Post: Delayed revocation of TLS certificates with Certificate Policies extension problem
#1887705 RESOLVED Delayed Revocation Opened 2024-03-25 · Closed 2024-09-12 · 88% similar
Entrust: Delayed revocation of clientAuth TLS Certificates without serverAuth EKU
#1896553 RESOLVED Delayed Revocation Opened 2024-05-14 · Closed 2025-02-12 · 88% similar
Telia: Delayed revocation of seven (7) certificates related to incident 1896108
#1886110 RESOLVED Delayed Revocation Opened 2024-03-19 · Closed 2025-02-14 · 88% similar
TWCA: Revocation delay for TLS certificates with non-critical basicConstraints
#1887888 RESOLVED Delayed Revocation Opened 2024-03-26 · Closed 2025-02-28 · 88% similar
Hongkong Post: Delayed revocation of TLS certificates with basicConstraints not marked as critical
#1903066 RESOLVED Delayed Revocation Opened 2024-06-17 · Closed 2025-02-12 · 88% similar
Chunghwa Telecom: Delayed Revocation with Controversial Extension (2.5.29.9, SubjectDirectoryAttributes)
#1888882 RESOLVED Delayed Revocation Opened 2024-04-01 · Closed 2025-03-27 · 88% similar
CFCA: Delayed revocation of TLS certificates(basicConstraints extension not marked as critical)

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action