← China Financial Certification Authority (CFCA) cases
Bugzilla #1809382 Ca Certificate Compliance

CFCA: Certificate with wrong crlDistributionPoints

RESOLVED FIXED China Financial Certification Authority (CFCA)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The China Financial Certification Authority (CFCA) discovered that three certificates it issued incorrectly marked the crlDistributionPoints as critical. This issue was identified on January 6, 2023, during a verification process using the CA/RA Zlint function. Upon discovery, CFCA promptly revoked the affected certificates and suspended the verification process until the issue was resolved. CFCA has since implemented a new plan to ensure proper functionality of the Zlint service and has completed the necessary upgrades to prevent future occurrences. The case has been resolved and is now closed.

Model: gpt-4o-mini Generated: 2026-06-13 21:29 UTC Revised: 2026-06-16 18:08 UTC Confidence: 0.90 21 comments
Chronology
  1. CFCA identified an issue with certificates marking crlDistributionPoints as critical.
  2. CFCA revoked the affected certificates.
  3. CFCA completed the upgrade of signing certificates with a throwaway key.
  4. The case was closed by Mozilla.
Thread Activity
  1. China Financial Certification Authority (CFCA) — CFCA reported the issue regarding the incorrect crlDistributionPoints.
  2. China Financial Certification Authority (CFCA) — CFCA provided a detailed timeline of actions taken in response to the issue.
  3. China Financial Certification Authority (CFCA) — CFCA confirmed the application of ZLint service.
  4. China Financial Certification Authority (CFCA) — CFCA reported completion of the upgrade process.
  5. Mozilla representative — Mozilla announced the closure of the case.
Participants
China Financial Certification Authority (CFCA) Google representative Internet Security Research Group Sectigo Mozilla representative
External References
Similar Local Cases
#1793053 RESOLVED Ca Certificate Compliance Opened 2022-09-30 · Closed 2023-06-30 · 100% similar
CFCA: ICA without EKU
#1802845 RESOLVED Ca Certificate Compliance Opened 2022-11-28 · Closed 2023-09-29 · 96% similar
CFCA: EV certificate with wrong PostalCode&Street
#1705337 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-04-15 · Closed 2023-02-22 · 69% similar
KIR S.A.: Invalid localityName + CRL Revoked but OCSP Unknown
#1887008 RESOLVED Ca Certificate Compliance Opened 2024-03-22 · Closed 2024-08-28 · 64% similar
Hongkong Post: TLS certificates with basicConstraints not marked as critical
#1685370 RESOLVED Ca Certificate Compliance Certificate Misissuance Revocation Issue Opened 2021-01-06 · Closed 2023-02-22 · 64% similar
Entrust: Incorrect Business Category Value Discovered in an EV SSL Certificate
#1598390 RESOLVED Ca Certificate Compliance Opened 2019-11-21 · Closed 2024-05-09 · 63% similar
Microsoft PKI Services: Null Character Bug and Microsoft Root CAs
#1718991 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-07-02 · Closed 2024-05-09 · 63% similar
Microsoft PKI Services: Malformed ICAs (Key Usage Malformed)
#1390991 RESOLVED Ca Certificate Compliance Incident Certificate Misissuance Opened 2017-08-16 · Closed 2023-02-22 · 63% similar
Disig: Non-BR-Compliant Certificate Issuance

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action