← China Financial Certification Authority (CFCA) cases
Bugzilla #1532429 Certificate Misissuance Self Reported Incident

CFCA: Invalid TLD in SAN

RESOLVED FIXED China Financial Certification Authority (CFCA)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The case concerns a CFCA-issued certificate that contained an invalid domain (invalid TLD) in the SAN, identified via crt.sh linting results. The initial issue was raised on the mozilla.dev.security.policy mailing list by Michael Le Bihan, referencing a crt.sh entry, and Rufus Buschart stated he had sent a certificate problem report to CFCA. CFCA confirmed the problem, stated the certificate had not been deployed to production systems, and said it had been revoked on March 1, 2019. CFCA also stated it fixed the underlying issue in a February 27 update and later provided details including that it had added a “hard fail” detection mechanism, stopped issuing certificates with this problem, and planned training and internal audits to prevent recurrence. In later comments, CFCA acknowledged delays in providing an update/incident report and described additional process attention and a second audit process. The bug was marked RESOLVED with resolution FIXED, and a final comment indicated remediation was completed.

Model: gpt-5.4-nano Generated: 2026-06-13 18:05 UTC Revised: 2026-06-16 18:04 UTC Confidence: 0.86 6 comments
Chronology
  1. CFCA checked its CA database and contacts after receiving posts and revoked the problematic certificate the same day.
  2. CFCA stated the problematic certificate was revoked.
  3. CFCA stated it fixed the issue by updating systems with a hard-fail mechanism.
Thread Activity
  1. Community commenter — Reported that a crt.sh entry showed an invalid domain `mail.xinhua08.con` in the SAN and noted that CFCA had been contacted via a certificate problem report.
  2. Community commenter — Confirmed the issue, said the certificate was not deployed to production, stated it was revoked in March 1, 2019, and said a fix was applied in a February 27 update; requested an incident report per Mozilla guidance.
  3. Community commenter — Asked for updates on the bug.
  4. Community commenter — Provided a detailed response including CFCA’s recognition of the problematic certificate, a timeline, revocation actions, process changes (hard-fail mechanism), training, and internal audits.
  5. Community commenter — Asked why an update/incident report had not been provided earlier and requested information on compliance/training changes for timely responses.
  6. Community commenter — Explained personnel changes, apologized for late responses, and stated they would pay more attention to Bugzilla, added a hard-fail mechanism, and added a second audit process.
  7. Community commenter — Stated it appeared all questions were answered and remediation was completed.
Participants
Community commenter
Related Bugzilla IDs Mentioned
Similar Local Cases
#1524733 RESOLVED Certificate Misissuance Opened 2019-02-02 · Closed 2023-02-22 · 85% similar
CFCA: invalid dnsNames
#1524143 RESOLVED Certificate Misissuance Opened 2019-01-31 · Closed 2023-02-22 · 82% similar
CFCA: Internal iPAddress in certificate
#1532113 RESOLVED Certificate Misissuance Self Reported Incident Opened 2019-03-03 · Closed 2023-02-22 · 70% similar
CFCA: O > 64 characters
#1532559 RESOLVED Certificate Misissuance Self Reported Incident Opened 2019-03-05 · Closed 2023-02-22 · 70% similar
CFCA: Wrong SerialNumber encoding
#2031281 RESOLVED Ca Certificate Compliance Self Reported Incident Incident Certificate Misissuance Opened 2026-04-13 · Closed 2026-06-16 · 69% similar
CFCA: OCSP Responder Certificate Profile Deviations and OCSP Service Issues
#1565494 RESOLVED Audit Finding Self Reported Incident Repository Issue Opened 2019-07-12 · Closed 2024-06-30 · 68% similar
CFCA: Missed annual CPS update publication on website in 2018
#1551369 RESOLVED Self Reported Incident Certificate Misissuance Opened 2019-05-14 · Closed 2023-02-22 · 66% similar
Kamu SM: "Some-State" in stateOrProvinceName
#1561013 RESOLVED Self Reported Incident Certificate Misissuance Opened 2019-06-24 · Closed 2023-02-22 · 66% similar
Entrust: Certificate issued with validity greater than 825-days

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action