← China Financial Certification Authority (CFCA) cases
Bugzilla #1888882
Delayed Revocation
CFCA: Delayed revocation of TLS certificates(basicConstraints extension not marked as critical)
CLOSED
FIXED
China Financial Certification Authority (CFCA)
AI Summary
The China Financial Certification Authority (CFCA) faced challenges in revoking 2,098 TLS certificates due to the basicConstraints extension not being marked as critical. Although CFCA initiated revocation within the required timeframe, they ultimately failed to revoke all affected certificates on time, citing issues such as customer contact difficulties and regulatory constraints. As of the latest updates, CFCA has revoked 2,070 certificates and has committed to improving their processes to ensure timely revocation in the future.
Chronology
- Initial email reminder sent to CFCA regarding certificate issues.
- CFCA reports 1,409 certificates revoked, with 689 remaining.
- Final remaining certificates revoked.
- CFCA submits closure summary and commits to timely revocation.
Participants
Gao Fei
Tim Callan
Ryan
External References
Similar Local Cases
CFCA: The delay in revocation of ICA
Entrust: Delayed revocation of clientAuth TLS Certificates without serverAuth EKU
Hongkong Post: Delayed revocation of TLS certificates with basicConstraints not marked as critical
Telekom Security: Revocation delay for TLS certificates with basicConstraints not marked as critical
Microsec: Delayed revocation of the misissued certificates
Hongkong Post: Delayed revocation of TLS certificates with Certificate Policies extension problem
Digicert: Delayed Revocation for bug 1894560
Buypass: Delayed revocation of TLS certificates