← China Financial Certification Authority (CFCA) cases
Bugzilla #1863122 Delayed Revocation

CFCA: CRL Error

RESOLVED FIXED China Financial Certification Authority (CFCA)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns CRL distribution point behavior for CFCA certificates, where Mozilla’s incident report indicated that the certificates’ cRLDistributionPoints used fragmented addresses and did not use Full CRL. The thread states that there were 2,761 valid certificates of this type. CFCA reported that a preliminary investigation found its crl_monitor was blacklisted by a network security policy, causing network errors during CRL detection. CFCA confirmed the certificate issue and determined a treatment plan: upgrade the CA system so newly issued certificates would use Full CRL, and adjust network policy so Full CRL could be downloaded using the address recorded in cRLDistributionPoints. CFCA stated that it completed the system upgrade on November 7 and that newly issued certificates contain the full CRL address, and it adjusted the CRL policy so certificates issued after 2023-01-15 can download the full CRL normally. The bug was resolved as FIXED, and Mozilla indicated it would be closed on 10-Jan-2024 if no further questions were raised.

Model: gpt-5.4-nano Generated: 2026-06-13 21:31 UTC Revised: 2026-06-16 18:08 UTC Confidence: 0.50 3 comments
Chronology
  1. CFCA completed a CA system upgrade so newly issued certificates use Full CRL addresses.
Thread Activity
  1. China Financial Certification Authority (CFCA) — CFCA described an incident report: 2,761 valid CFCA certificates used fragmented cRLDistributionPoints and did not use Full CRL, and CFCA planned an upgrade and network policy adjustment to enable Full CRL download.
  2. China Financial Certification Authority (CFCA) — CFCA stated the system upgrade was completed on Nov 7 and the newly issued certificates contain Full CRL addresses, and that the CRL policy was adjusted for certificates issued after 2023-01-15.
  3. Mozilla representative — Mozilla asked whether there were additional questions or comments and said it would close the bug on Wed 10-Jan-2024 if none were raised.
Participants
China Financial Certification Authority (CFCA) Community commenter Mozilla representative
External References
Similar Local Cases
#1798812 RESOLVED Delayed Revocation Opened 2022-11-02 · Closed 2023-05-04 · 100% similar
CFCA: Delayed reporting of revocation of an intermediate CA certificate
#1888882 RESOLVED Delayed Revocation Opened 2024-04-01 · Closed 2025-03-27 · 94% similar
CFCA: Delayed revocation of TLS certificates(basicConstraints extension not marked as critical)
#1793059 RESOLVED Delayed Revocation Opened 2022-09-30 · Closed 2023-06-30 · 78% similar
CFCA: The delay in revocation of ICA
#1804753 RESOLVED Delayed Revocation Opened 2022-12-08 · Closed 2023-04-19 · 70% similar
Entrust: Delayed Revocation for EV TLS Certificate incorrect jurisdiction
#1927675 RESOLVED Delayed Revocation Opened 2024-10-29 · Closed 2024-12-02 · 69% similar
iTrusChina: CPR was not responded to within 24 hours
#1792111 RESOLVED Delayed Revocation Incident Opened 2022-09-22 · Closed 2023-02-22 · 69% similar
IdenTrust: Expired CRLs
#1634795 RESOLVED Revocation Issue Delayed Revocation Opened 2020-05-01 · Closed 2023-02-22 · 69% similar
Google Trust Services: Incorrect revocation data temporarily served for GTS Y3 & Y4
#1639798 RESOLVED Delayed Revocation Opened 2020-05-21 · Closed 2023-02-22 · 69% similar
GoDaddy: Failure to revoke key-compromised certificates within 24 hours

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action