← China Financial Certification Authority (CFCA) cases
Bugzilla #1863122
Certificate Problem Report
CFCA: CRL Error
RESOLVED
FIXED
China Financial Certification Authority (CFCA)
AI Summary
The China Financial Certification Authority (CFCA) faced an issue with its certificate revocation list (CRL) due to the use of fragmented addresses instead of a Full CRL. This problem was identified by Rob Stradling, leading to a preliminary investigation that revealed a network security policy issue. CFCA has since upgraded its system and adjusted its CRL policy, ensuring that newly issued certificates now contain the correct Full CRL addresses. The issue affected a total of 2,761 certificates, but the CRL function remained operational and did not impact verification processes.
Chronology
- Ben Wilson inquires about CRL detection errors.
- CFCA confirms the issue with fragmented addresses.
- CFCA completes system upgrade, issuing certificates with Full CRL.
Participants
Gao Fei
Rob Stradling
Ben Wilson
External References
Similar Local Cases
CFCA: Certificate with wrong crlDistributionPoints
CFCA: Delayed reporting of revocation of an intermediate CA certificate
CFCA: EV certificate with wrong PostalCode&Street
CFCA: certificate basicConstraints extension not marked as critical
CFCA: ICA without EKU
CFCA: Precertificate with postalCode and streetAddress swapped
CFCA: Failure to respond to a CPR in a complete and/or timely manner
Digicert: Preview certificate uploaded to CCADB instead of the actual certificate