← China Financial Certification Authority (CFCA) cases
Bugzilla #1793053
Certificate Problem Report
CFCA: ICA without EKU
RESOLVED
FIXED
China Financial Certification Authority (CFCA)
AI Summary
The China Financial Certification Authority (CFCA) addressed a certificate issue where an Intermediate Certificate Authority (ICA) lacked the Extended Key Usage (EKU) extension. This problem was identified on August 15, 2022, following a report from Ryan Dickson. CFCA took immediate action by revoking the affected ICA and implementing a series of improvements, including the introduction of automated detection tools to prevent future occurrences. The case has been resolved, and CFCA has committed to ongoing enhancements in their certificate issuance processes.
Chronology
- Received report about ICA lacking EKU extension.
- Revoked the ICA (CFCA DV OCA).
- Case resolved and closed.
Participants
Gao Fei
Ryan Dickson
CCADB team
External References
Similar Local Cases
CFCA: certificate basicConstraints extension not marked as critical
CFCA: Delayed reporting of revocation of an intermediate CA certificate
CFCA: Certificate with wrong crlDistributionPoints
CFCA: EV certificate with wrong PostalCode&Street
CFCA: Failure to respond to a CPR in a complete and/or timely manner
CFCA: CRL Error
CFCA: O > 64 characters
CFCA: Invalid TLD in SAN