CFCA OCSP unauthorized responses for three G2 intermediate CA certificates; incident report closed and final call issued
This case concerns CFCA’s OCSP responders returning “unauthorized” for three intermediate CA certificates under CFCA_Global_RSA_ROOT_G2: CFCA_DV_RSA_OCA_G2, CFCA_OV_RSA_OCA_G2, and CFCA_EV_RSA_OCA_G2. CFCA reported that the OCSP responder infrastructure had not been deployed when the hierarchy was created, and that the required responder signing certificates, OCSP database entries, and responder service were not provisioned. CFCA later said the OCSP service was deployed and verified operational for all three intermediates on 2026-07-04. The thread also covered a separate CPR mailbox-monitoring failure: CFCA first gave an incorrect explanation for why an email report was missed, then corrected that explanation and said the message had been in the inbox but was not found because the review used an inadequate keyword-only search. CFCA said it had established a dedicated CPR email address, updated its action items, and moved the CPR-handling items to Bug #2054464. On 2026-07-27, CFCA posted a closure report stating that all action items in this bug were complete and requested closure, and CCADB issued a final call for comments with closure expected around 2026-08-03.
- CFCA_Global_RSA_ROOT_G2 and its three intermediate CA certificates were issued.
- A CPR email was sent to c**********i@cfca.com.cn.
- A CPR was submitted through the web form after OCSPWatch detected unauthorized responses.
- CFCA deployed and verified OCSP service for all three intermediate CA certificates.
- CFCA posted a closure report requesting closure of the incident report.
- China Financial Certification Authority (CFCA) — Opened the bug with a preliminary incident report describing unauthorized OCSP responses for the three intermediate CA certificates.
- Community commenter — Said the issue had been reported to c**********i@cfca.com.cn and noted the same email address on the CPR page.
- China Financial Certification Authority (CFCA) — Said CFCA searched the mailbox and found no matching email, and suggested the message may not have reached the server.
- Community commenter — Objected to CFCA’s speculative delivery explanation and said both the web form and email fallback had failed.
- China Financial Certification Authority (CFCA) — Posted the full incident report, including the OCSP deployment date and the incident timeline.
- China Financial Certification Authority (CFCA) — Corrected the earlier mailbox-search claim, withdrew the delivery speculation, and said the email was missed because of keyword-only monitoring.
- China Financial Certification Authority (CFCA) — Updated the action items, removed some CPR-mailbox items from this bug, and said they would be tracked in Bug #2054464.
- China Financial Certification Authority (CFCA) — Said there were no further updates yet.
- China Financial Certification Authority (CFCA) — Posted a closure report stating that the OCSP issue was remediated and all action items in this bug were complete.
- CCADB representative — Issued a final call for comments or questions and said the bug would be closed around 2026-08-03.