← China Financial Certification Authority (CFCA) cases
Bugzilla #1565494
Policy Compliance
CFCA: Missed annual CPS update publication on website in 2018
RESOLVED
FIXED
China Financial Certification Authority (CFCA)
AI Summary
The China Financial Certification Authority (CFCA) missed the annual publication of its Certification Practice Statement (CPS) in 2018, which was required under Mozilla's policies. CFCA acknowledged the oversight, citing internal business adjustments and compliance evaluations as contributing factors. The updated CPS was eventually published on August 9, 2019, following a significant delay. This incident raised concerns about CFCA's ability to meet compliance deadlines and effectively communicate issues to Mozilla.
Chronology
- CFCA updated CPS to version 3.3
- CT requirements in effect; work begins on CPS version 4.0
- Failed to meet requirement to update CPS annually
- Incident reported
- Version 4.0 of CPS published
Participants
Oliver Bi
Wayne Thayer
External References
Similar Local Cases
Sectigo: Missing Changelog in CPS
Sectigo: Failure to revoke certificate with previously-compromised key within 24 hours
SwissSign: BRs require full annual audits
Firmaprofesional: Missing BR Self Assessment
Ernst & Young Poland: KIR OCSP "unknown" status for revoked certificate
DigiCert: Inconsistent EV audits
ACCV: Missing BR Self Assessment
GoDaddy: Non-BR-Compliant Certificate Issuance