CFCA: DV OCA caIssuers Returns PEM Encoded Certificate (RFC 5280 Section 4.2.2.1 Violation)
The China Financial Certification Authority (CFCA) identified a compliance issue where the caIssuers HTTP link in the CFCA DV OCA certificate returned a PEM encoded certificate instead of the required DER format, violating RFC 5280 Section 4.2.2.1. This issue was discovered following a report from a community member. CFCA has since updated the caIssuers link to return the correct DER encoded certificates and conducted a thorough review of their certificate hierarchy to ensure compliance. All action items related to this incident have been completed, and a commitment to enhance internal compliance training has been made to prevent future occurrences.
- CFCA confirmed the issue after receiving a report from a community member.
- CFCA completed remediation by updating the caIssuers link to return DER encoded certificates.
- CFCA submitted a final incident report and requested closure of the case.
- Community commenter — Preliminary Incident Report submitted detailing the compliance issue.
- Community commenter — Full Incident Report submitted with a comprehensive analysis and remediation steps.
- Community commenter — Closure summary provided, confirming all action items have been completed.