← China Financial Certification Authority (CFCA) cases
Bugzilla #1949131 Self Reported Incident

CFCA: BasicConstraints are not marked as critical certificates are missing and therefore not revoked

RESOLVED FIXED China Financial Certification Authority (CFCA)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The China Financial Certification Authority (CFCA) reported a compliance issue where the basicConstraints extension of certain certificates was not marked as critical. This issue was initially identified in late March 2024, leading to the revocation of over 2,000 certificates issued between September 15, 2023, and March 19, 2024. Following a notification from Chris Clements on February 10, 2025, CFCA confirmed three additional certificates with the same issue and completed their revocation shortly thereafter. CFCA has since implemented measures to prevent similar issues in the future and has committed to ongoing improvements in compliance with the CA/B Forum Requirements.

Model: gpt-4o-mini Generated: 2026-06-13 21:34 UTC Revised: 2026-06-16 18:09 UTC Confidence: 0.85 23 comments
Chronology
  1. CFCA completed the revocation of over 2,000 non-compliant certificates.
  2. CFCA was notified of three certificates with basicConstraints not marked as critical.
  3. CFCA completed the revocation of the three identified certificates.
Thread Activity
  1. China Financial Certification Authority (CFCA) — CFCA confirmed the issue and began revoking affected certificates.
  2. Google representative — Inquired about the timeline for the Full Incident Report.
  3. China Financial Certification Authority (CFCA) — Provided a detailed Full Incident Report addressing the compliance issue.
  4. Google representative — Requested clarification on related incidents and compliance with reporting guidelines.
  5. Community commenter — Filed a new bug to address the reporting timeline violation.
Participants
China Financial Certification Authority (CFCA) Google representative Community commenter
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
#1959733 RESOLVED Self Reported Incident Opened 2025-04-10 · Closed 2025-07-16 · 93% similar
CFCA: Failed to respond a Certificate Problem Report within 24 hours which violates Section 4.9.5 of the TLS BRs
#2005399 RESOLVED Incident Self Reported Incident Opened 2025-12-11 · Closed 2026-02-18 · 90% similar
CFCA: DV OCA caIssuers Returns PEM Encoded Certificate (RFC 5280 Section 4.2.2.1 Violation)
#1955799 RESOLVED Self Reported Incident Opened 2025-03-23 · Closed 2025-04-11 · 87% similar
CFCA: Failed to follow Report lifecycle rule to respond within 7 days
#2009134 RESOLVED Self Reported Incident Opened 2026-01-08 · Closed 2026-02-18 · 87% similar
CFCA: reporting delayed when handling incident bug #2005399
#2033412 RESOLVED Ca Certificate Compliance Externally Reported Incident Incident Certificate Misissuance Opened 2026-04-20 · Closed 2026-06-25 · 87% similar
CFCA: CRL signatureAlgorithm Missing NULL Parameter (RFC 4055 Section 5)
#2031281 RESOLVED Ca Certificate Compliance Self Reported Incident Incident Certificate Misissuance Opened 2026-04-13 · Closed 2026-06-16 · 86% similar
CFCA: OCSP Responder Certificate Profile Deviations and OCSP Service Issues
#1532559 RESOLVED Certificate Misissuance Self Reported Incident Opened 2019-03-05 · Closed 2023-02-22 · 84% similar
CFCA: Wrong SerialNumber encoding
#1532113 RESOLVED Certificate Misissuance Self Reported Incident Opened 2019-03-03 · Closed 2023-02-22 · 82% similar
CFCA: O > 64 characters

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action