Government of Korea: Misissuance detected by PKIMetal
The Government of Korea, KLID, acknowledged a misissuance incident involving certain OV TLS Subscriber Certificates issued under the legacy GPKIRootCA1 hierarchy. The issues were identified by PKIMetal and included prohibited key usage and improper CRL distribution points. Following the report, KLID initiated an incident investigation, revoked the affected certificates, and conducted a comprehensive review of all valid certificates. As of June 5, 2026, all identified non-compliant certificates have been revoked, and KLID has committed to strengthening its internal controls to prevent future occurrences. A full incident report was published detailing the timeline and actions taken.
- Bug 2032478 was opened, reporting certificate profile issues.
- KLID became technically aware of the shared profile issue.
- KLID revoked the initially identified certificates.
- KLID confirmed that all affected certificates were revoked.
- CCADB representative — Report of misissuance issues detected by PKIMetal.
- Klid representative — KLID acknowledged the issues and initiated an incident investigation.
- Klid representative — KLID provided a full incident report summary.
- Klid representative — KLID confirmed all affected certificates were revoked.