← China Financial Certification Authority (CFCA) cases
Bugzilla #1778035
Certificate Problem Report
CFCA: The wrong status of OCSP
RESOLVED
FIXED
China Financial Certification Authority (CFCA)
AI Summary
The China Financial Certification Authority (CFCA) reported an issue with the Online Certificate Status Protocol (OCSP) where some cache data was not synchronized following an update in May. This led to an abnormal OCSP status affecting approximately 14 certificates from May 5 to June 15, 2022. CFCA took corrective actions by updating their systems, and the issue was resolved. They have since implemented measures to enhance their testing methods and are developing a linting tool to prevent future mis-issuances.
Chronology
- Received report about a wrongly issued certificate.
- Replaced the wrongly issued certificate and revoked it.
- Updated the test system to fix the OCSP issue.
- Applied ZLint service for certificate issuance.
Participants
bixinlong@cfca.com.cn
gaofei@cfca.com.cn
bwilson@mozilla.com
ryandickson@google.com
External References
Similar Local Cases
CFCA: Certificate with wrong crlDistributionPoints
Telia: Issued three precertificates with non-NIST EC curve
CFCA: certificate basicConstraints extension not marked as critical
E-Tugra: Incident Report (Security Issues)
TWCA: Revocation delay for TLS certificates with non-critical basicConstraints
CFCA: EV certificate with wrong PostalCode&Street
CFCA: Wrong SerialNumber encoding
CFCA: Delayed reporting of revocation of an intermediate CA certificate