← China Financial Certification Authority (CFCA) cases
Bugzilla #1524733
Certificate Problem Report
CFCA: invalid dnsNames
RESOLVED
FIXED
China Financial Certification Authority (CFCA)
AI Summary
The China Financial Certification Authority (CFCA) issued two certificates with invalid dnsNames, which were reported by Jonathan Rudenberg. Upon notification, CFCA revoked both certificates on the same day. The incident highlighted a lack of a 'Hard fail' detection mechanism, leading to reliance on manual reviews. CFCA has since implemented system updates and training to prevent future misissuance, including automated checks for compliance with standards.
Chronology
- CFCA received reports of invalid dnsNames.
- CFCA revoked the problematic certificates.
- CFCA implemented a 'Hard fail' detection mechanism.
- CFCA completed internal training on BR requirements.
- CFCA submitted a final report on the incident.
Participants
Jonathan Rudenberg
Jonathan Sun
Wayne Thayer
Ryan Sleevi
External References
Similar Local Cases
CFCA: Wrong SerialNumber encoding
CFCA: Invalid TLD in SAN
CFCA: Internal iPAddress in certificate
CFCA: O > 64 characters
GoDaddy: failure to revoke underscores
CFCA: Wrong OrganizationName
Sectigo: "Some-State" in stateOrProvinceName
TrustCor: Insufficient Serial Number Entropy