← China Financial Certification Authority (CFCA) cases
Bugzilla #1793059
Delayed Revocation
CFCA: The delay in revocation of ICA
RESOLVED
FIXED
China Financial Certification Authority (CFCA)
AI Summary
The China Financial Certification Authority (CFCA) faced a delay in revoking an Intermediate Certificate Authority (ICA) due to an oversight in their revocation process. The ICA, created on June 23, 2021, lacked an Extended Key Usage (EKU) extension and was reported on August 15, 2022. CFCA took corrective actions, including revoking the ICA on September 19, 2022, and implementing new procedures to prevent future delays. The case has been resolved, with CFCA committing to improved monitoring and response protocols.
Chronology
- Created new ICA - CFCA DV OCA
- Reported CFCA DV OCA in CCADB
- Received report about missing EKU extension
- Revoked the ICA (CFCA DV OCA)
Participants
Gao Fei
Ryan Dickson
Bi Xinlong
Li Kairui
Qiu Dawei
External References
Similar Local Cases
CFCA: Delayed revocation of TLS certificates(basicConstraints extension not marked as critical)
Asseco DS / Certum: Delayed revocation of SHECA cross certificate
Hongkong Post: Delayed revocation of TLS certificates with Certificate Policies extension problem
Hongkong Post: Delayed revocation of TLS certificates with basicConstraints not marked as critical
Asseco DS / Certum: Delayed revocation of SSL.COM cross certificate
Asseco DS / Certum: Delayed revocation of SSL.COM cross certificate
HARICA: delayed revocation for bug 1943596
NetLock: Delayed revocation report connected to ticket 1680378