← China Financial Certification Authority (CFCA) cases
Bugzilla #2006333 Certificate Misissuance

CFCA: EV Certificates misissued with incorrect businessCategory

RESOLVED FIXED China Financial Certification Authority (CFCA)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The China Financial Certification Authority (CFCA) identified that several Extended Validation (EV) certificates issued to Chinese government entities were incorrectly classified as 'Private Organization' instead of 'Government Entity'. This misclassification was discovered following a Certificate Problem Report from security researchers on December 5, 2025. CFCA confirmed 16 affected certificates, of which 14 were active and revoked by December 12, 2025. A subsequent inspection revealed an additional 27 certificates with similar issues, all of which were revoked by December 26, 2025. CFCA has since implemented corrective measures, including updates to their system logic and enhanced vetting processes to prevent future occurrences.

Model: gpt-4o-mini Generated: 2026-06-13 21:36 UTC Revised: 2026-06-16 18:10 UTC Confidence: 0.85 25 comments
Chronology
  1. CFCA received a Certificate Problem Report from security researchers regarding misclassification of EV certificates.
  2. CFCA revoked 14 non-compliant certificates identified in the initial report.
  3. CFCA completed the revocation of an additional 27 certificates found during further inspection.
  4. CFCA submitted a closure report after completing all action items related to the incident.
Thread Activity
  1. Community commenter — CFCA identified misissued EV certificates and began the investigation.
  2. Community commenter — CFCA found 27 more EV certificates with the same issue and initiated revocation.
  3. Community commenter — CFCA provided a full incident report detailing the misissuance and corrective actions taken.
  4. Community commenter — CFCA submitted the closure report as all action items were completed.
Participants
Community commenter Gmx representative CCADB representative
External References
Similar Local Cases
#1838371 RESOLVED Certificate Misissuance Opened 2023-06-14 · Closed 2024-01-19 · 84% similar
CFCA: certificate with an incorrect OrganizationName
#2031281 RESOLVED Ca Certificate Compliance Self Reported Incident Incident Certificate Misissuance Opened 2026-04-13 · Closed 2026-06-16 · 74% similar
CFCA: OCSP Responder Certificate Profile Deviations and OCSP Service Issues
#1977253 RESOLVED Certificate Misissuance Opened 2025-07-14 · Closed 2025-09-15 · 67% similar
Sectigo: OV reuse data applied for wrong organization
#2012326 RESOLVED Certificate Misissuance Opened 2026-01-25 · Closed 2026-02-27 · 67% similar
FNMT: Issuance of certificate using keys previously reported as compromised
#2032468 ASSIGNED Ca Certificate Compliance Certificate Misissuance Problem Reporting Failure Audit Finding Opened 2026-04-16 Still Open · 66% similar
VISA: Misissuance detected by PKIMetal
#2023458 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2026-03-15 · Closed 2026-06-12 · 66% similar
D-Trust: TLS Precertificates Exceeding the Maximum Validity Period Allowed by the TLS Baseline Requirements
#2032473 ASSIGNED Ca Certificate Compliance Incident Externally Reported Incident Certificate Misissuance Opened 2026-04-16 Still Open · 65% similar
CCA India: Misissuance detected by PKIMetal
#1966515 RESOLVED Certificate Misissuance Opened 2025-05-14 · Closed 2025-06-04 · 65% similar
Let's Encrypt: Issuance for Invalid Internationalized Domain Name

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action