← China Financial Certification Authority (CFCA) cases
Bugzilla #1886135
Certificate Problem Report
CFCA: certificate basicConstraints extension not marked as critical
RESOLVED
FIXED
China Financial Certification Authority (CFCA)
AI Summary
The China Financial Certification Authority (CFCA) identified an issue where the basicConstraints extension in several SSL certificates was not marked as critical. Upon receiving a report from a user, CFCA promptly halted certificate issuance and rectified the issue. A total of 2,098 certificates were affected, and CFCA has since implemented measures to prevent future occurrences, including upgrading their linting tools and revising incident handling procedures. The incident has been resolved, and CFCA is now focused on compliance and monitoring improvements.
Chronology
- CFCA confirmed the issue and stopped issuing certificates.
- CFCA resumed certificate issuance after fixing the issue.
- CFCA completed revocation of 840 affected certificates.
- CFCA completed all improvement measures.
Participants
Gao Fei
Ryan Dickson
External References
Similar Local Cases
CFCA: ICA without EKU
CFCA: Delayed reporting of revocation of an intermediate CA certificate
CFCA: Certificate with wrong crlDistributionPoints
CFCA: EV certificate with wrong PostalCode&Street
CFCA: Failure to respond to a CPR in a complete and/or timely manner
CFCA: CRL Error
CFCA: Precertificate with postalCode and streetAddress swapped
CFCA: The wrong status of OCSP