← China Financial Certification Authority (CFCA) cases
Bugzilla #1809382
Certificate Problem Report
CFCA: Certificate with wrong crlDistributionPoints
RESOLVED
FIXED
China Financial Certification Authority (CFCA)
AI Summary
The China Financial Certification Authority (CFCA) identified an issue where three certificates were issued with incorrect crlDistributionPoints marked as critical. This error was discovered during a verification process on January 6, 2023, leading to the immediate revocation of the affected certificates. CFCA has since implemented corrective measures, including a re-optimization of their Zlint verification process, to prevent future occurrences. The issue has been resolved, and CFCA has committed to ongoing improvements in their certificate issuance processes.
Chronology
- CFCA discovered the issue with crlDistributionPoints during verification.
- CFCA revoked the three affected certificates.
- CFCA completed the application of ZLint service.
- CFCA completed the upgrade of signing certificates with a throwaway key.
- Case marked for closure.
Participants
Gao Fei
Chris Clements
Aaron Gable
Rob Stradling
Brett Wilson
External References
Similar Local Cases
CFCA: CRL Error
CFCA: EV certificate with wrong PostalCode&Street
CFCA: Delayed reporting of revocation of an intermediate CA certificate
CFCA: certificate basicConstraints extension not marked as critical
CFCA: ICA without EKU
Let's Encrypt: Duplicate Serial Numbers
Let's Encrypt: Failure to provide OCSP Responses for some certificates
CFCA: Failure to respond to a CPR in a complete and/or timely manner