← China Financial Certification Authority (CFCA) cases
Bugzilla #1838371
Certificate Misissuance
CFCA: certificate with an incorrect OrganizationName
RESOLVED
FIXED
China Financial Certification Authority (CFCA)
AI Summary
The China Financial Certification Authority (CFCA) issued an OV SSL certificate for the domain www.hncdi.gov.cn, which incorrectly listed the organization as Hainan New Realm Software Co., Ltd. instead of the actual registrant, the Hainan Provincial Commission for Discipline Inspection of the Communist Party of China. Following reports of this misissuance, CFCA acknowledged the error and initiated the revocation of 22 affected certificates. They have also revised their verification processes to ensure future compliance with standards.
Chronology
- CFCA issued certificate for www.hncdi.gov.cn
- Misissuance reported by user
- CFCA confirmed revocation of certificates
- Certificates revoked
Participants
2018@duck.com
gaofei@cfca.com.cn
bwilson@mozilla.com
rob@sectigo.com
amir@aaomidi.com
External References
Similar Local Cases
IdenTrust: unintended creation of a Root CA certificate
SSL.com: Issuance of one Sponsored-Validated S/MIME certificate with organization information in givenName and surName of the subjectDN
iTrusChina: Issuance of certificates using keys previously reported as compromised
Hongkong Post: Invalid EV cert businessCategory
NAVER Cloud Trust Services: DV Certificate issued with improperly validated
CFCA: EV Certificates misissued with incorrect businessCategory
CFCA: BasicConstraints are not marked as critical certificates are missing and therefore not revoked
HARICA: S/MIME certificate issuance with incorrect commonName