← China Financial Certification Authority (CFCA) cases
Bugzilla #2005399 Incident Self Reported Incident

CFCA: DV OCA caIssuers Returns PEM Encoded Certificate (RFC 5280 Section 4.2.2.1 Violation)

RESOLVED FIXED China Financial Certification Authority (CFCA)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The China Financial Certification Authority (CFCA) identified a compliance issue where the caIssuers HTTP link in the CFCA DV OCA certificate returned a PEM encoded certificate instead of the required DER format, violating RFC 5280 Section 4.2.2.1. This issue was discovered following a report from a community member. CFCA has since updated the caIssuers link to return the correct DER encoded certificates and conducted a thorough review of their certificate hierarchy to ensure compliance. All action items related to this incident have been completed, and a commitment to enhance internal compliance training has been made to prevent future occurrences.

Model: gpt-4o-mini Generated: 2026-06-13 21:35 UTC Revised: 2026-06-16 18:10 UTC Confidence: 0.85 15 comments
Chronology
  1. CFCA confirmed the issue after receiving a report from a community member.
  2. CFCA completed remediation by updating the caIssuers link to return DER encoded certificates.
  3. CFCA submitted a final incident report and requested closure of the case.
Thread Activity
  1. Community commenter — Preliminary Incident Report submitted detailing the compliance issue.
  2. Community commenter — Full Incident Report submitted with a comprehensive analysis and remediation steps.
  3. Community commenter — Closure summary provided, confirming all action items have been completed.
Participants
Community commenter Apple representative
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
#2009134 RESOLVED Self Reported Incident Opened 2026-01-08 · Closed 2026-02-18 · 91% similar
CFCA: reporting delayed when handling incident bug #2005399
#1949131 RESOLVED Self Reported Incident Opened 2025-02-19 · Closed 2025-05-08 · 90% similar
CFCA: BasicConstraints are not marked as critical certificates are missing and therefore not revoked
#1955799 RESOLVED Self Reported Incident Opened 2025-03-23 · Closed 2025-04-11 · 89% similar
CFCA: Failed to follow Report lifecycle rule to respond within 7 days
#2031281 RESOLVED Ca Certificate Compliance Self Reported Incident Incident Certificate Misissuance Opened 2026-04-13 · Closed 2026-06-16 · 88% similar
CFCA: OCSP Responder Certificate Profile Deviations and OCSP Service Issues
#1959733 RESOLVED Self Reported Incident Opened 2025-04-10 · Closed 2025-07-16 · 87% similar
CFCA: Failed to respond a Certificate Problem Report within 24 hours which violates Section 4.9.5 of the TLS BRs
#2004699 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Repository Issue Opened 2025-12-08 Still Open · 86% similar
Netlock: CA in AIA in PEM format
#1532559 RESOLVED Certificate Misissuance Self Reported Incident Opened 2019-03-05 · Closed 2023-02-22 · 83% similar
CFCA: Wrong SerialNumber encoding
#1532113 RESOLVED Certificate Misissuance Self Reported Incident Opened 2019-03-03 · Closed 2023-02-22 · 81% similar
CFCA: O > 64 characters

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action