← China Financial Certification Authority (CFCA) cases
Bugzilla #1959733 Self Reported Incident

CFCA self-reported late response to Certificate Problem Reports and updated its reporting process

RESOLVED FIXED China Financial Certification Authority (CFCA)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

CFCA self-reported that it failed to respond to Certificate Problem Reports within the 24-hour timeframe required by Section 4.9.5 of the TLS Baseline Requirements. The report says CPR emails sent to CFCA’s CCADB-disclosed address were not received, and CFCA initially investigated the issue as a possible email filtering problem outside its control. CFCA later updated its incident report with new findings, including that the CPR had been sent to a Sina address and that the earlier assessment was incomplete. As remediation, CFCA implemented a web form for CPR submission, added automation to notify its team, and arranged multiple staff to check CPR mailboxes with a double-check process. The bug was closed as RESOLVED/FIXED after CFCA stated that all action items were completed and requested closure.

Model: gpt-5.4-mini Generated: 2026-06-13 21:34 UTC Revised: 2026-06-16 18:10 UTC Confidence: 0.97 31 comments
Chronology
  1. A CPR was sent to CFCA’s CCADB-disclosed email address and was not responded to within 24 hours.
  2. CFCA filed a self-reported incident about the late CPR response.
  3. CFCA said it had implemented a CPR web form, automation, and updated its CP/CPS.
  4. The bug remained resolved with CFCA asking for closure after stating there were no further questions.
Thread Activity
  1. Community commenter — CFCA opened the bug and said it had failed to respond to CPR emails within the TLS BR 24-hour requirement.
  2. Community commenter — CFCA posted a full incident report describing the issue as self-reported, with no certificates impacted and an action item to change the problem-reporting address.
  3. Community commenter — CFCA said it could access Gmail via VPN and that it was using Gmail to avoid missing notifications.
  4. HARICA — Dimitris Zacharopoulos suggested reviewing related incidents and considering a web form for CPR submissions.
  5. Google representative — Google’s Chrome Root Program recommended reviewing related incidents and tracking the action item more formally.
  6. Community commenter — CFCA updated the incident report, saying it found the CPR had been sent to a Sina email address and revised the report with new findings.
  7. Community commenter — CFCA said it had arranged two staff to check the mailbox daily and added automation to retrieve emails every four hours.
  8. Community commenter — CFCA reported that the web form and automation were implemented and that all action items were completed.
  9. CCADB representative — CCADB incident reporting asked CFCA to provide a closure report if the case was ready for closure.
  10. Community commenter — CFCA submitted a closure summary and requested closure of the incident.
  11. CCADB representative — CCADB issued a final call for comments and said the bug would be closed around 2025-07-15.
  12. Community commenter — CFCA asked for the bug to be closed and said it had kept its 7-day reply timing in mind.
Participants
Community commenter Cooperjr representative HARICA Google representative CCADB representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1955799 RESOLVED Self Reported Incident Opened 2025-03-23 · Closed 2025-04-11 · 100% similar
CFCA: Failed to follow Report lifecycle rule to respond within 7 days
#1949131 RESOLVED Self Reported Incident Opened 2025-02-19 · Closed 2025-05-08 · 93% similar
CFCA: BasicConstraints are not marked as critical certificates are missing and therefore not revoked
#2009134 RESOLVED Self Reported Incident Opened 2026-01-08 · Closed 2026-02-18 · 90% similar
CFCA: reporting delayed when handling incident bug #2005399
#2033412 RESOLVED Ca Certificate Compliance Externally Reported Incident Incident Certificate Misissuance Opened 2026-04-20 · Closed 2026-06-25 · 89% similar
CFCA: CRL signatureAlgorithm Missing NULL Parameter (RFC 4055 Section 5)
#2031281 RESOLVED Ca Certificate Compliance Self Reported Incident Incident Certificate Misissuance Opened 2026-04-13 · Closed 2026-06-16 · 88% similar
CFCA: OCSP Responder Certificate Profile Deviations and OCSP Service Issues
#2005399 RESOLVED Incident Self Reported Incident Opened 2025-12-11 · Closed 2026-02-18 · 87% similar
CFCA: DV OCA caIssuers Returns PEM Encoded Certificate (RFC 5280 Section 4.2.2.1 Violation)
#1955365 RESOLVED Self Reported Incident Opened 2025-03-20 · Closed 2025-05-19 · 85% similar
Apple: Public Key Reuse
#1981680 RESOLVED Ca Certificate Compliance Self Reported Incident Certificate Misissuance Linting Quality Issue Opened 2025-08-07 · Closed 2025-09-26 · 84% similar
TunTrust: SSL OV mis-issuance against CP/CPS (Email attribute)

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action