← China Financial Certification Authority (CFCA) cases
Bugzilla #1532559
Certificate Problem Report
CFCA: Wrong SerialNumber encoding
RESOLVED
FIXED
China Financial Certification Authority (CFCA)
AI Summary
The China Financial Certification Authority (CFCA) faced an issue with the encoding of the SerialNumber in a certificate, which was reported by a user in March 2019. CFCA acknowledged the problem, stating that it was due to a bug related to UTF-8 character encoding. The problematic certificate was revoked, and CFCA implemented a new automated audit and issuance system to enhance compliance and prevent future issues. Despite some delays in reporting and revocation, CFCA has committed to improving their processes and ensuring timely incident reporting in the future.
Chronology
- CFCA noticed potential issues with SerialNumber encoding.
- CFCA modified the encoding issue.
- CA system updated to fix the problem.
- Issue reported by user Michel Le Bihan.
- Certificate marked as revoked.
- Internal training on new system completed.
- Planned launch of the automated system after Spring Festival.
Participants
Michel Le Bihan
Jonathan Sun
Ryan Sleevi
Wayne Thayer
Sunny Bi
External References
Similar Local Cases
CFCA: invalid dnsNames
CFCA: O > 64 characters
CFCA: Invalid TLD in SAN
CFCA: Internal iPAddress in certificate
CFCA: Precertificate with postalCode and streetAddress swapped
CFCA: Wrong OrganizationName
SwissSign: CP/CPS certificate profile issue
Telekom Security: Multiple commonName in certificates