← China Financial Certification Authority (CFCA) cases
Bugzilla #2031281 Certificate Problem Report

CFCA: OCSP Responder Certificate Profile Deviations and OCSP Service Issues

ASSIGNED China Financial Certification Authority (CFCA)
AI Summary

The China Financial Certification Authority (CFCA) faced multiple non-conformance issues with its OCSP Responder certificates, including unauthorized Key Usage flags, missing required extensions, and prohibited extensions. These issues were reported by a third-party security researcher on April 7, 2026. The incident was not detected in a timely manner due to the disclosure being made outside the official Certificate Problem Report mechanism. CFCA has since reissued the affected certificates and implemented several corrective actions, including updates to their compliance processes and infrastructure checks.

Model: gpt-4o-mini Generated: 2026-06-13 21:37 UTC Confidence: 0.90
Chronology
  1. CFCA received a report from a security researcher regarding OCSP Responder certificate issues.
  2. All OCSP Responder certificates were reissued with correct profiles.
  3. CFCA submitted a closure report detailing remediation actions taken.
Participants
songxinlei@gmail.com
External References
Similar Local Cases
#1959733 RESOLVED Certificate Problem Report Opened 2025-04-10 · Closed 2025-07-16 · 59% similar
CFCA: Failed to respond a Certificate Problem Report within 24 hours which violates Section 4.9.5 of the TLS BRs
#2033412 ASSIGNED Certificate Problem Report Opened 2026-04-20 Still Open · 53% similar
CFCA: CRL signatureAlgorithm Missing NULL Parameter (RFC 4055 Section 5)
#1524733 RESOLVED Certificate Problem Report Opened 2019-02-02 · Closed 2023-02-22 · 53% similar
CFCA: invalid dnsNames
#1532559 RESOLVED Certificate Problem Report Opened 2019-03-05 · Closed 2023-02-22 · 53% similar
CFCA: Wrong SerialNumber encoding
#1886135 RESOLVED Certificate Problem Report Opened 2024-03-19 · Closed 2024-09-26 · 53% similar
CFCA: certificate basicConstraints extension not marked as critical
#1532429 RESOLVED Certificate Problem Report Opened 2019-03-04 · Closed 2023-02-22 · 52% similar
CFCA: Invalid TLD in SAN
#1798812 RESOLVED Certificate Problem Report Opened 2022-11-02 · Closed 2023-05-04 · 52% similar
CFCA: Delayed reporting of revocation of an intermediate CA certificate
#1802845 RESOLVED Certificate Problem Report Opened 2022-11-28 · Closed 2023-09-29 · 52% similar
CFCA: EV certificate with wrong PostalCode&Street

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action