← China Financial Certification Authority (CFCA) cases
Bugzilla #1169490 Ca Certificate Root Program Incident Closure Request

remove CFCA CA from FF

RESOLVED INVALID China Financial Certification Authority (CFCA)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This bug requests removing the CFCA CA from Firefox, asserting that Firefox 38 “silently injects” an untrustworthy CA from a “totalitarian country,” specifically CFCA. The reporter claims that such CAs can forge arbitrary certificates without being noticed and argues that CFCA should be removed to protect users. A Mozilla participant responded that the request should not be treated as security sensitive and pointed to bug 926029 for an inclusion request, asking for more information about practices that violate Mozilla policies before a CA would be removed. The reporter argued that the obvious nature of the concern was sufficient and referenced past cases involving other CAs. The Mozilla participant stated they suspected no concrete evidence of violations would be forthcoming and marked the bug invalid. The bug is currently resolved as INVALID.

Model: gpt-5.4-nano Generated: 2026-06-13 14:00 UTC Revised: 2026-06-16 18:02 UTC Confidence: 0.50 5 comments
Chronology
  1. Bug 1169490 was filed requesting removal of the CFCA root from Firefox.
Thread Activity
  1. Scientia representative — Reported that Firefox 38 injects CFCA and requested its removal, alleging the CA is inherently untrustworthy and can forge arbitrary certificates.
  2. Bclary representative — Asked for more information about policy-violating practices and referenced bug 926029, leaving the bug open to allow the opportunity to provide details.
  3. Scientia representative — Argued that no further information beyond the obvious is needed and cited past CA forgery-related cases.
  4. Bclary representative — Marked the bug INVALID, stating they suspected no concrete evidence of violations would be forthcoming.
  5. Scientia representative — Made additional remarks about Mozilla and intelligence agencies.
Participants
Scientia representative Bclary representative
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
#1918427 RESOLVED Ca Certificate Compliance Incident Closure Request Opened 2024-09-12 · Closed 2024-10-11 · 68% similar
D-Trust: Non-compliance of issued root and intermediate S/MIME certificates
#1582519 RESOLVED Incident Opened 2019-09-19 · Closed 2022-11-14 · 60% similar
DigiCert: Apple: Precertificates without corresponding certificates return OCSP value of "unknown"
#1475563 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2018-07-13 · Closed 2022-11-14 · 60% similar
GDCA: Misissuance of certificates with IP address
#1367842 RESOLVED Ca Certificate Compliance Incident Opened 2017-05-25 · Closed 2023-02-22 · 58% similar
TurkTrust: Non-audited, non-technically-constrained intermediate certs
#926029 RESOLVED Ca Certificate Root Program Root Inclusion Opened 2013-10-12 · Closed 2022-11-14 · 58% similar
CFCA (China Financial Certification Authority) root CA
#1620727 RESOLVED Ca Certificate Compliance Incident Opened 2020-03-07 · Closed 2023-02-22 · 57% similar
Microsoft DSRE PKI: OCSP responders found to respond signed by the default CA when passed an invalid issuer in request
#2007116 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Externally Reported Incident Opened 2025-12-19 Still Open · 57% similar
D-Trust: CRL URL Disclosure
#1398246 RESOLVED Ca Certificate Compliance Incident Opened 2017-09-08 · Closed 2023-02-22 · 57% similar
Consorci AOC: Non-BR-Compliant OCSP Responders

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action