← China Financial Certification Authority (CFCA) cases
Bugzilla #2031281 Ca Certificate Compliance Self Reported Incident Incident Certificate Misissuance Validation Issue

CFCA OCSP responder certificate profile deviations and OCSP service issues

RESOLVED FIXED China Financial Certification Authority (CFCA)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

CFCA reported a compliance incident involving its OCSP infrastructure after a security researcher emailed the company about multiple non-conformance issues. The reported problems included OCSP responder certificate profile deviations, an OCSP service returning "unauthorized" for subordinate CA certificate status queries, and a separate CRL encoding issue that CFCA later split into another bug. CFCA stated that the issues were first received by email and were not initially processed through the official public CPR mechanism. CFCA later identified the OCSP-related issues as affecting three OCSP responder certificates and one subordinate CA certificate, and said the OCSP responder certificates were reissued with corrected profiles. The report was updated through action items, and CFCA stated that all action items were completed and requested closure.

Model: gpt-5.4-mini Generated: 2026-06-13 21:37 UTC Revised: 2026-06-19 19:26 UTC Confidence: 0.97 18 comments
Chronology
  1. CFCA received a third-party report about OCSP responder certificate profile deviations and OCSP service issues.
  2. CFCA separated the CRL signatureAlgorithm issue into Bug 2033412.
  3. CFCA said the OCSP responder certificates had been reissued with correct BR 7.1.2.8 profiles.
  4. CFCA submitted a closure report stating that all action items were completed and requesting closure.
Thread Activity
  1. Community commenter — CFCA opened a preliminary incident report describing third-party reported OCSP profile deviations and OCSP service issues.
  2. CCADB representative — Mozilla/CCADB asked that distinct and unrelated root causes be tracked in separate bugs.
  3. Community commenter — CFCA said it had split the CRL-related issues into Bug 2033412 and renamed this bug to focus on OCSP issues.
  4. Community commenter — CFCA reported that the OCSP responder certificates had been reissued and updated the action items table.
  5. Community commenter — CFCA posted a report closure summary stating the remediation was complete and requesting closure.
  6. CCADB representative — CCADB issued a final call for comments or questions before closure.
Participants
Community commenter CCADB representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#2033412 RESOLVED Ca Certificate Compliance Externally Reported Incident Incident Certificate Misissuance Opened 2026-04-20 · Closed 2026-06-25 · 97% similar
CFCA: CRL signatureAlgorithm Missing NULL Parameter (RFC 4055 Section 5)
#1959733 RESOLVED Self Reported Incident Opened 2025-04-10 · Closed 2025-07-16 · 88% similar
CFCA: Failed to respond a Certificate Problem Report within 24 hours which violates Section 4.9.5 of the TLS BRs
#2005399 RESOLVED Incident Self Reported Incident Opened 2025-12-11 · Closed 2026-02-18 · 88% similar
CFCA: DV OCA caIssuers Returns PEM Encoded Certificate (RFC 5280 Section 4.2.2.1 Violation)
#1979475 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-07-26 · Closed 2026-01-20 · 82% similar
Microsoft PKI Services: End Entity Certificate Mis-issuance against CPS (BasicConstraints)
#1999850 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Revocation Issue Opened 2025-11-13 · Closed 2026-07-01 · 80% similar
Microsoft PKI Services: OCSP Non-Compliance
#2014590 RESOLVED Self Reported Incident Incident Opened 2026-02-04 · Closed 2026-04-23 · 80% similar
IdenTrust: Unauthorized OCSP responses for cross-signed roots
#2016267 RESOLVED Self Reported Incident Incident Opened 2026-02-11 · Closed 2026-04-17 · 80% similar
IdenTrust: Gap between audit periods
#2026351 RESOLVED Self Reported Incident Certificate Misissuance Opened 2026-03-25 · Closed 2026-05-18 · 80% similar
Identrust: Root CrossSign, of dedicated Roots, missing EKU

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action