GDCA delayed revocation of SSL/TLS certificates with non-critical Basic Constraints
GDCA reported that it had issued 20 SSL/TLS certificates with the Basic Constraints extension present but not marked critical, and that 13 of those certificates were not revoked within the 5-day Baseline Requirements deadline after the issue was confirmed. The case was triggered by a certificate problem report received from a third party on 2024-03-26, after which GDCA confirmed the issue, opened a preliminary incident report, and began contacting affected customers. GDCA said all affected certificates were either revoked or expired by 2024-04-02, and it later provided an updated incident report, per-subscriber rationale, and a closure summary. Mozilla asked for clearer root-cause analysis, per-subscriber explanations, and stronger remediation tied to preventing future delayed revocation. GDCA described remediation steps including a rapid revocation response team, revised subscriber agreement language, emergency contact collection, revocation drills, and linting improvements, and Mozilla indicated the bug would remain open until those requirements were satisfied before closure.
- First problematic SSL/TLS certificate was issued with Basic Constraints not set as critical.
- Last problematic SSL/TLS certificate was issued.
- A third party reported the certificate problem to GDCA.
- GDCA confirmed the issue and published a preliminary incident report.
- GDCA completed revocation of all problematic certificates.
- GDCA posted an incident closure summary and requested closure.
- Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) — GDCA opened a preliminary incident report stating that 13 certificates had not been revoked within 5 days of receiving the certificate problem report.
- Mozilla representative — Mozilla asked whether full remediation had occurred and requested more concrete lessons learned about customer communication.
- Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) — GDCA said it had optimized its communication strategy and updated its internal approval process for certificate replacement.
- Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) — GDCA said it would increase customer support resources and provide 7x24 technical support during certificate replacement.
- Mozilla representative — Mozilla said the bug would remain open until GDCA provided a clear commitment to improve its treatment of revocations and an updated incident report.
- Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) — GDCA posted an updated incident report with revised root-cause analysis and additional remediation items.
- Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) — GDCA provided a per-subscriber rationale attachment and said it had not consulted its auditor about the revocation-delay risk analysis before the 5-day window expired.
- Mozilla representative — Mozilla said the bug would remain open until at least 2025-02-01 while incident-reporting and compliance work continued.
- Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) — GDCA filed an incident closure summary stating that all listed action items had been completed and requesting closure.
- Mozilla representative — Mozilla said it intended to close the bug on 2025-04-02 unless there were further questions or issues.