← China Financial Certification Authority (CFCA) cases
Bugzilla #2033412
Certificate Problem Report
CFCA: CRL signatureAlgorithm Missing NULL Parameter (RFC 4055 Section 5)
ASSIGNED
China Financial Certification Authority (CFCA)
AI Summary
The China Financial Certification Authority (CFCA) reported an issue where the CRL signatureAlgorithm field was missing a required NULL parameter for RSA algorithms, as specified in RFC 4055 Section 5. This non-compliance was identified on April 7, 2026, and affected four CRLs. The issue was disclosed by a third party and has been addressed through a series of corrective actions, including software fixes and CRL regeneration, which were completed by June 10, 2026.
Chronology
- CABatch CRL generation software deployed, introducing ASN.1 encoding deficiency.
- Non-compliance identified.
- All action items completed, including CRL regeneration.
Participants
Michael
External References
Similar Local Cases
CFCA: Failure to respond to a CPR in a complete and/or timely manner
CFCA: reporting delayed when handling incident bug #2006333
CFCA: OCSP Responder Certificate Profile Deviations and OCSP Service Issues
CFCA: O > 64 characters
CFCA: ICA without EKU
CFCA: Invalid TLD in SAN
CFCA: The wrong status of OCSP
CFCA: Certificate with wrong crlDistributionPoints