CFCA: CRL Error
This case concerns CRL distribution point behavior for CFCA certificates, where Mozilla’s incident report indicated that the certificates’ cRLDistributionPoints used fragmented addresses and did not use Full CRL. The thread states that there were 2,761 valid certificates of this type. CFCA reported that a preliminary investigation found its crl_monitor was blacklisted by a network security policy, causing network errors during CRL detection. CFCA confirmed the certificate issue and determined a treatment plan: upgrade the CA system so newly issued certificates would use Full CRL, and adjust network policy so Full CRL could be downloaded using the address recorded in cRLDistributionPoints. CFCA stated that it completed the system upgrade on November 7 and that newly issued certificates contain the full CRL address, and it adjusted the CRL policy so certificates issued after 2023-01-15 can download the full CRL normally. The bug was resolved as FIXED, and Mozilla indicated it would be closed on 10-Jan-2024 if no further questions were raised.
- CFCA completed a CA system upgrade so newly issued certificates use Full CRL addresses.
- China Financial Certification Authority (CFCA) — CFCA described an incident report: 2,761 valid CFCA certificates used fragmented cRLDistributionPoints and did not use Full CRL, and CFCA planned an upgrade and network policy adjustment to enable Full CRL download.
- China Financial Certification Authority (CFCA) — CFCA stated the system upgrade was completed on Nov 7 and the newly issued certificates contain Full CRL addresses, and that the CRL policy was adjusted for certificates issued after 2023-01-15.
- Mozilla representative — Mozilla asked whether there were additional questions or comments and said it would close the bug on Wed 10-Jan-2024 if none were raised.