← China Financial Certification Authority (CFCA) cases
Bugzilla #1565494 Audit Finding Self Reported Incident Repository Issue

CFCA: Missed annual CPS update publication on website in 2018

RESOLVED FIXED China Financial Certification Authority (CFCA)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns China Financial Certification Authority (CFCA) missing the annual publication of an updated Certification Practice Statement (CPS) on its website in 2018. CFCA stated that it maintained annual updates to its Global Trust CPS as requested by Mozilla and Google, but that major business adjustments in 2018 (including stopping code signing in March 2018 and revoking subordinate CAs in October 2018) delayed updating the CPS from version 3.3 to version 4.0, resulting in the missed 2018 publication. In response to Mozilla’s questions, CFCA said it became aware of the failure in December 2018 and that it was not familiar with the reporting mechanism until it was reminded, after which it submitted the report. CFCA later stated that the CPS was published on August 9 and provided a link to the updated CPS document. Mozilla’s reviewer noted the delay and the lack of notification about the publication delay, and then resolved the bug after stating that remediation appeared complete. The bug was marked FIXED and the thread indicates the updated CPS publication was completed.

Model: gpt-5.4-nano Generated: 2026-06-13 18:17 UTC Revised: 2026-06-16 18:05 UTC Confidence: 0.86 8 comments
Chronology
  1. CFCA revoked subordinate code signing CAs (CFCA EV CodeSign OCA and CFCA OV CodeSign OCA).
  2. CFCA identified that it had not published the required annual CPS update.
  3. CFCA published version 4.0 of its Global Trust CPS on its website.
Thread Activity
  1. Community commenter — Created the bug and explained that business changes in 2018 delayed updating CPS from V3.3 to V4.0, leading to the missed 2018 annual publication.
  2. Fastly representative — Asked Oliver to remove the security-sensitive flag from the bug.
  3. Fastly representative — Requested CFCA update its answers to clarify how CFCA discovered the violation and challenged whether the current CPS complied with the BRs.
  4. Community commenter — Responded that CFCA became aware of the issue due to major business adjustments and described internal document compilation/approval timing and future controls to prevent delays.
  5. Fastly representative — Asked whether the new CPS had been published and criticized the lack of notification and the time taken to publish.
  6. Community commenter — Stated CFCA became aware in December 2018, said it was reminded about the reporting mechanism, and reported that the CPS was published on August 9 with a provided URL.
  7. Fastly representative — Acknowledged remediation appeared complete, expressed concerns about the delay and notification failure, and resolved the bug.
  8. Community commenter — Acknowledged the mistake, apologized, and said CFCA would solve related problems timely.
Participants
Community commenter Fastly representative
Similar Local Cases
#1608333 RESOLVED Self Reported Incident Opened 2020-01-10 · Closed 2023-02-22 · 96% similar
CFCA: Wrong OrganizationName
#1532113 RESOLVED Certificate Misissuance Self Reported Incident Opened 2019-03-03 · Closed 2023-02-22 · 94% similar
CFCA: O > 64 characters
#1532559 RESOLVED Certificate Misissuance Self Reported Incident Opened 2019-03-05 · Closed 2023-02-22 · 94% similar
CFCA: Wrong SerialNumber encoding
#1955799 RESOLVED Self Reported Incident Opened 2025-03-23 · Closed 2025-04-11 · 81% similar
CFCA: Failed to follow Report lifecycle rule to respond within 7 days
#2009134 RESOLVED Self Reported Incident Opened 2026-01-08 · Closed 2026-02-18 · 81% similar
CFCA: reporting delayed when handling incident bug #2005399
#1959733 RESOLVED Self Reported Incident Opened 2025-04-10 · Closed 2025-07-16 · 79% similar
CFCA: Failed to respond a Certificate Problem Report within 24 hours which violates Section 4.9.5 of the TLS BRs
#1949131 RESOLVED Self Reported Incident Opened 2025-02-19 · Closed 2025-05-08 · 78% similar
CFCA: BasicConstraints are not marked as critical certificates are missing and therefore not revoked
#2005399 RESOLVED Incident Self Reported Incident Opened 2025-12-11 · Closed 2026-02-18 · 78% similar
CFCA: DV OCA caIssuers Returns PEM Encoded Certificate (RFC 5280 Section 4.2.2.1 Violation)

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action