← China Financial Certification Authority (CFCA) cases
Bugzilla #2033412 Ca Certificate Compliance Externally Reported Incident Incident Certificate Misissuance Linting Quality Issue

CFCA CRL encoding incident: missing RSA NULL parameter and empty revokedCertificates field

RESOLVED FIXED China Financial Certification Authority (CFCA)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

CFCA reported a CRL encoding incident affecting four CRLs: the RSA signatureAlgorithm field was missing the required NULL parameter, and one DVOCA CRL also had an empty revokedCertificates field when no certificates were revoked. The issue was first identified by a third party, XiPKI, and CFCA’s compliance team then began incident response after forwarded reports were received. CFCA stated that the problem affected CRL infrastructure only, did not affect subscriber certificates or issuance, and OCSP revocation checking continued to function normally. CFCA separated this CRL issue from Bug 2031281, completed the listed remediation steps, and filed a closure report requesting that the incident report be closed. The thread shows a final call for comments from CCADB, with closure expected around 2026-06-23 if no further questions were raised.

Model: gpt-5.4-mini Generated: 2026-06-13 21:37 UTC Revised: 2026-06-26 17:46 UTC Confidence: 0.97 13 comments
Chronology
  1. CABatch CRL generation software was deployed with an ASN.1 encoding deficiency affecting RSA signatureAlgorithm encoding.
  2. The CRL encoding issue was identified and CFCA employees received forwarded reports.
  3. CFCA manually verified that all four CRLs had the signatureAlgorithm encoding issue, and the DVOCA CRL empty revokedCertificates issue was self-discovered.
  4. CFCA completed the fixes and regenerated the affected CRLs.
  5. CFCA submitted a closure report requesting the incident report be closed.
Thread Activity
  1. Community commenter — Opened the bug with a preliminary incident report describing the CRL signatureAlgorithm NULL-parameter issue and noting it was reported by XiPKI.
  2. Community commenter — Posted the full incident report, including impact, timeline, affected CRL URLs, and the fact that the issue was reported by a third party.
  3. Community commenter — Reported that all action items had been completed and listed the completed remediation steps.
  4. Community commenter — Posted the closure report and requested closure of the incident report.
  5. CCADB representative — Issued a final call for comments and said the report would be closed around 2026-06-23 if there were no further questions.
Participants
Community commenter CCADB representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#2031281 RESOLVED Ca Certificate Compliance Self Reported Incident Incident Certificate Misissuance Opened 2026-04-13 · Closed 2026-06-16 · 97% similar
CFCA: OCSP Responder Certificate Profile Deviations and OCSP Service Issues
#2058918 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-07-29 Still Open · 82% similar
CFCA: Incorrect countryName values in OV subscriber certificates
#2032063 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-04-15 · Closed 2026-07-06 · 82% similar
Hongkong Post: Certificates with invalid embedded SCT signature
#2056223 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-07-20 · Closed 2026-08-08 · 81% similar
D-Trust OCSP Responder Certificates Include CA/B Forum DV Policy OID
#2056668 RESOLVED Self Reported Incident Policy Document Issue Incident Opened By Ca Opened 2026-07-21 · Closed 2026-08-31 · 80% similar
HARICA: Issuance of Server TLS Certificates without AIA OCSP URI against CP/CPS
#2058503 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-07-28 · Closed 2026-09-02 · 80% similar
GlobalSign: SubCA created with incorrect CPS Policy OID
#2052399 RESOLVED Incident Self Reported Incident Repository Issue Remediation Tracking Opened 2026-07-03 · Closed 2026-08-08 · 80% similar
Certainly: Expired certificates on "Valid" and "Revoked" test websites
#2067050 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-08-27 Still Open · 79% similar
CFCA: Cross-signed certificate missing the Extended Key Usage (EKU) extension

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action