← China Financial Certification Authority (CFCA) cases
Bugzilla #1608333 Self Reported Incident

CFCA: Wrong OrganizationName

RESOLVED FIXED China Financial Certification Authority (CFCA)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case reports that China Financial Certification Authority (CFCA) issued two wrong certificates for testing purposes with an incorrect OrganizationName. The issue was triggered during a test mission that included certificate application, revocation, and update, when a test engineer inadvertently issued the two error certificates. CFCA states that both certificates were revoked quickly: one was revoked by the test engineer and the other was revoked about one hour later after an auditor noticed the problem, with the overall process taking less than two hours. CFCA also reports follow-up actions including restricting the test engineer’s permissions to the minimum scope and planning to add professional auditors and training for future testing. In response to Mozilla’s questions, CFCA stated it reviewed user permissions and testing procedures, and it planned additional technical restrictions (such as preventing multiple different roles from logging in from the same IP) and involving product and compliance managers in review. The bug was marked RESOLVED with resolution FIXED, and a later comment indicated remediation was complete.

Model: gpt-5.4-nano Generated: 2026-06-13 21:02 UTC Revised: 2026-06-16 18:05 UTC Confidence: 0.86 5 comments
Chronology
  1. CFCA’s test engineer inadvertently issued two test certificates with the wrong OrganizationName, which were later revoked the same day.
  2. CFCA reported the incident in the Mozilla CA Program bug and described remediation steps.
  3. A participant stated that all questions were answered and remediation was complete.
Thread Activity
  1. Community commenter — Created the report describing two wrong OrganizationName certificates issued during testing, noting they were revoked quickly and that test engineer permissions were restricted afterward.
  2. Community commenter — Asked for further details on root cause analysis and follow-up, including permission review, ensuring testing procedures are followed, monitoring for revocation events, and clarification of the planned auditor training.
  3. Community commenter — Provided responses to the follow-up questions, stating permissions and testing procedures were reviewed and describing planned technical restrictions and increased involvement/training of professional auditors.
  4. Fastly representative — Stated that it appears all questions were answered and remediation is complete.
Participants
Community commenter Fastly representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1532113 RESOLVED Certificate Misissuance Self Reported Incident Opened 2019-03-03 · Closed 2023-02-22 · 100% similar
CFCA: O > 64 characters
#1532559 RESOLVED Certificate Misissuance Self Reported Incident Opened 2019-03-05 · Closed 2023-02-22 · 100% similar
CFCA: Wrong SerialNumber encoding
#1565494 RESOLVED Audit Finding Self Reported Incident Repository Issue Opened 2019-07-12 · Closed 2024-06-30 · 96% similar
CFCA: Missed annual CPS update publication on website in 2018
#1955799 RESOLVED Self Reported Incident Opened 2025-03-23 · Closed 2025-04-11 · 82% similar
CFCA: Failed to follow Report lifecycle rule to respond within 7 days
#1949131 RESOLVED Self Reported Incident Opened 2025-02-19 · Closed 2025-05-08 · 80% similar
CFCA: BasicConstraints are not marked as critical certificates are missing and therefore not revoked
#1959733 RESOLVED Self Reported Incident Opened 2025-04-10 · Closed 2025-07-16 · 80% similar
CFCA: Failed to respond a Certificate Problem Report within 24 hours which violates Section 4.9.5 of the TLS BRs
#2005399 RESOLVED Incident Self Reported Incident Opened 2025-12-11 · Closed 2026-02-18 · 79% similar
CFCA: DV OCA caIssuers Returns PEM Encoded Certificate (RFC 5280 Section 4.2.2.1 Violation)
#2033412 RESOLVED Ca Certificate Compliance Externally Reported Incident Incident Certificate Misissuance Opened 2026-04-20 · Closed 2026-06-25 · 79% similar
CFCA: CRL signatureAlgorithm Missing NULL Parameter (RFC 4055 Section 5)

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action