← China Financial Certification Authority (CFCA) cases
Bugzilla #2033412 Ca Certificate Compliance Externally Reported Incident Incident Certificate Misissuance Linting Quality Issue

CFCA CRL encoding incident: missing RSA NULL parameter and empty revokedCertificates field

RESOLVED FIXED China Financial Certification Authority (CFCA)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

CFCA reported a CRL encoding incident affecting four CRLs: the RSA signatureAlgorithm field was missing the required NULL parameter, and one DVOCA CRL also had an empty revokedCertificates field when no certificates were revoked. The issue was first identified by a third party, XiPKI, and CFCA’s compliance team then began incident response after forwarded reports were received. CFCA stated that the problem affected CRL infrastructure only, did not affect subscriber certificates or issuance, and OCSP revocation checking continued to function normally. CFCA separated this CRL issue from Bug 2031281, completed the listed remediation steps, and filed a closure report requesting that the incident report be closed. The thread shows a final call for comments from CCADB, with closure expected around 2026-06-23 if no further questions were raised.

Model: gpt-5.4-mini Generated: 2026-06-13 21:37 UTC Revised: 2026-06-26 17:46 UTC Confidence: 0.97 13 comments
Chronology
  1. CABatch CRL generation software was deployed with an ASN.1 encoding deficiency affecting RSA signatureAlgorithm encoding.
  2. The CRL encoding issue was identified and CFCA employees received forwarded reports.
  3. CFCA manually verified that all four CRLs had the signatureAlgorithm encoding issue, and the DVOCA CRL empty revokedCertificates issue was self-discovered.
  4. CFCA completed the fixes and regenerated the affected CRLs.
  5. CFCA submitted a closure report requesting the incident report be closed.
Thread Activity
  1. Community commenter — Opened the bug with a preliminary incident report describing the CRL signatureAlgorithm NULL-parameter issue and noting it was reported by XiPKI.
  2. Community commenter — Posted the full incident report, including impact, timeline, affected CRL URLs, and the fact that the issue was reported by a third party.
  3. Community commenter — Reported that all action items had been completed and listed the completed remediation steps.
  4. Community commenter — Posted the closure report and requested closure of the incident report.
  5. CCADB representative — Issued a final call for comments and said the report would be closed around 2026-06-23 if there were no further questions.
Participants
Community commenter CCADB representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#2031281 RESOLVED Ca Certificate Compliance Self Reported Incident Incident Certificate Misissuance Opened 2026-04-13 · Closed 2026-06-16 · 97% similar
CFCA: OCSP Responder Certificate Profile Deviations and OCSP Service Issues
#2032063 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-04-15 · Closed 2026-07-06 · 82% similar
Hongkong Post: Certificates with invalid embedded SCT signature
#2011314 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Externally Reported Incident Opened 2026-01-19 · Closed 2026-06-23 · 79% similar
Netlock: unspecifed revocation code (0) in CRL
#1969296 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-05-29 · Closed 2025-07-22 · 79% similar
GoDaddy: Certificates with invalid embedded SCT signatures
#2004732 RESOLVED Ca Certificate Compliance Incident Opened 2025-12-08 · Closed 2026-01-05 · 79% similar
Certigna: AIA CA issuer field pointing to PEM encoded cert
#2021175 RESOLVED Ca Certificate Compliance Incident Opened 2026-03-05 · Closed 2026-04-03 · 78% similar
Microsoft PKI Services: Failure to update action item status within 3 days
#2021550 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2026-03-06 · Closed 2026-03-26 · 78% similar
SECOM: 2025 S/MIME CA Modified Opinion Report of Cybertrust Japan (CTJ)
#1986968 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-09-04 · Closed 2026-04-06 · 78% similar
Financijska agencija (Fina): Mis-issued certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action