← China Financial Certification Authority (CFCA) cases
Bugzilla #2005399
Certificate Problem Report
CFCA: DV OCA caIssuers Returns PEM Encoded Certificate (RFC 5280 Section 4.2.2.1 Violation)
RESOLVED
FIXED
China Financial Certification Authority (CFCA)
AI Summary
The CFCA DV OCA certificate was found to return a PEM encoded certificate instead of the required DER format as specified by RFC 5280. This issue was identified through a community report and has since been resolved by updating the caIssuers link to return the correct DER encoded certificate. A comprehensive review of all subordinate CA certificates was conducted to ensure compliance, and additional validation measures have been implemented to prevent future occurrences. The incident highlights the importance of adhering to RFC specifications and improving internal monitoring processes.
Chronology
- Non-compliance identified
- Remediation completed
- Incident report closure requested
Participants
Michael Songxinlei
External References
Similar Local Cases
CFCA: reporting delayed when handling incident bug #2005399
CFCA: certificate basicConstraints extension not marked as critical
CFCA: EV certificate with wrong PostalCode&Street
CFCA: O > 64 characters
CFCA: The wrong status of OCSP
CFCA: Delayed reporting of revocation of an intermediate CA certificate
CFCA: Certificate with wrong crlDistributionPoints
CFCA: Invalid TLD in SAN