← China Financial Certification Authority (CFCA) cases
Bugzilla #2009134
Certificate Problem Report
CFCA: reporting delayed when handling incident bug #2005399
RESOLVED
FIXED
China Financial Certification Authority (CFCA)
AI Summary
The China Financial Certification Authority (CFCA) reported a delay in filing an incident report related to Bug #2005399. The delay of two days was due to a misconception that remediation needed to be completed before the report could be filed, which is contrary to the Incident Reporting Guidelines requiring disclosure within 72 hours. CFCA has since updated their internal incident handling guidelines to align with community requirements and completed all action items related to this incident.
Chronology
- Non-compliance identified regarding incident reporting timeline.
- Bug #2009134 filed, marking the end of the non-compliance period.
- Final call for comments on the incident report before closure.
Participants
Michael Songxinlei
Dexter Dopping
External References
Similar Local Cases
CFCA: reporting delayed when handling incident bug #2006333
CFCA: DV OCA caIssuers Returns PEM Encoded Certificate (RFC 5280 Section 4.2.2.1 Violation)
CFCA: Failed to respond a Certificate Problem Report within 24 hours which violates Section 4.9.5 of the TLS BRs
CFCA: Delayed reporting of revocation of an intermediate CA certificate
CFCA: Failure to respond to a CPR in a complete and/or timely manner
CFCA: Wrong SerialNumber encoding
CFCA: Internal iPAddress in certificate
CFCA: invalid dnsNames