← China Financial Certification Authority (CFCA) cases
Bugzilla #1949131 Certificate Misissuance

CFCA: BasicConstraints are not marked as critical certificates are missing and therefore not revoked

RESOLVED FIXED China Financial Certification Authority (CFCA)
AI Summary

The China Financial Certification Authority (CFCA) identified that the basicConstraints extension of certain certificates was not marked as critical, leading to the issuance of non-compliant certificates. Following a notification from a third party, CFCA revoked over 2,000 certificates between September 2023 and March 2024. Despite the revocation efforts, three certificates issued in January 2024 were found to be non-compliant. CFCA has since implemented measures to prevent similar issues in the future, including system upgrades and improved revocation processes.

Model: gpt-4o-mini Generated: 2026-06-13 21:34 UTC Confidence: 0.90
Chronology
  1. TLS BR 2.0.0 takes effect; certificates issued do not meet basicConstraints requirements.
  2. CFCA completes system configuration change to mark basicConstraints as critical.
  3. CFCA is notified of three non-compliant certificates.
  4. CFCA revokes the last of the identified non-compliant certificates.
Participants
Gao Fei
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
#2006333 RESOLVED Certificate Misissuance Opened 2025-12-16 · Closed 2026-03-10 · 53% similar
CFCA: EV Certificates misissued with incorrect businessCategory
#1838371 RESOLVED Certificate Misissuance Opened 2023-06-14 · Closed 2024-01-19 · 51% similar
CFCA: certificate with an incorrect OrganizationName
#1888060 RESOLVED Certificate Misissuance Opened 2024-03-27 · Closed 2025-03-05 · 47% similar
GDCA: Issuance of SSL/TLS certificates with Non-critical Basic Constraints
#1965459 RESOLVED Certificate Misissuance Opened 2025-05-09 · Closed 2025-10-31 · 44% similar
Telia: S/MIME Misissuance incorrect AIA id-ca-caIssuer http:URI
#1524567 RESOLVED Certificate Misissuance Opened 2019-02-01 · Closed 2023-02-22 · 43% similar
Telia: invalid IP value in SAN DNS field
#1691704 RESOLVED Certificate Misissuance Opened 2021-02-09 · Closed 2023-02-22 · 43% similar
SwissSign: Certificate with key length 4098 bit
#1715929 RESOLVED Certificate Misissuance Opened 2021-06-11 · Closed 2023-02-22 · 43% similar
Sectigo: Incorrect EV businessCategory
#1720744 RESOLVED Certificate Misissuance Opened 2021-07-15 · Closed 2023-02-22 · 43% similar
Sectigo: State name in localityName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action