CFCA: Invalid TLD in SAN
The case concerns a CFCA-issued certificate that contained an invalid domain (invalid TLD) in the SAN, identified via crt.sh linting results. The initial issue was raised on the mozilla.dev.security.policy mailing list by Michael Le Bihan, referencing a crt.sh entry, and Rufus Buschart stated he had sent a certificate problem report to CFCA. CFCA confirmed the problem, stated the certificate had not been deployed to production systems, and said it had been revoked on March 1, 2019. CFCA also stated it fixed the underlying issue in a February 27 update and later provided details including that it had added a “hard fail” detection mechanism, stopped issuing certificates with this problem, and planned training and internal audits to prevent recurrence. In later comments, CFCA acknowledged delays in providing an update/incident report and described additional process attention and a second audit process. The bug was marked RESOLVED with resolution FIXED, and a final comment indicated remediation was completed.
- CFCA checked its CA database and contacts after receiving posts and revoked the problematic certificate the same day.
- CFCA stated the problematic certificate was revoked.
- CFCA stated it fixed the issue by updating systems with a hard-fail mechanism.
- Community commenter — Reported that a crt.sh entry showed an invalid domain `mail.xinhua08.con` in the SAN and noted that CFCA had been contacted via a certificate problem report.
- Community commenter — Confirmed the issue, said the certificate was not deployed to production, stated it was revoked in March 1, 2019, and said a fix was applied in a February 27 update; requested an incident report per Mozilla guidance.
- Community commenter — Asked for updates on the bug.
- Community commenter — Provided a detailed response including CFCA’s recognition of the problematic certificate, a timeline, revocation actions, process changes (hard-fail mechanism), training, and internal audits.
- Community commenter — Asked why an update/incident report had not been provided earlier and requested information on compliance/training changes for timely responses.
- Community commenter — Explained personnel changes, apologized for late responses, and stated they would pay more attention to Bugzilla, added a hard-fail mechanism, and added a second audit process.
- Community commenter — Stated it appeared all questions were answered and remediation was completed.