← China Financial Certification Authority (CFCA) cases
Bugzilla #2049179 Ca Certificate Compliance Incident Externally Reported Incident Revocation Issue Remediation Tracking

CFCA OCSP unauthorized responses for three G2 intermediate CA certificates; incident report closed and final call issued

ASSIGNED China Financial Certification Authority (CFCA)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns CFCA’s OCSP responders returning “unauthorized” for three intermediate CA certificates under CFCA_Global_RSA_ROOT_G2: CFCA_DV_RSA_OCA_G2, CFCA_OV_RSA_OCA_G2, and CFCA_EV_RSA_OCA_G2. CFCA reported that the OCSP responder infrastructure had not been deployed when the hierarchy was created, and that the required responder signing certificates, OCSP database entries, and responder service were not provisioned. CFCA later said the OCSP service was deployed and verified operational for all three intermediates on 2026-07-04. The thread also covered a separate CPR mailbox-monitoring failure: CFCA first gave an incorrect explanation for why an email report was missed, then corrected that explanation and said the message had been in the inbox but was not found because the review used an inadequate keyword-only search. CFCA said it had established a dedicated CPR email address, updated its action items, and moved the CPR-handling items to Bug #2054464. On 2026-07-27, CFCA posted a closure report stating that all action items in this bug were complete and requested closure, and CCADB issued a final call for comments with closure expected around 2026-08-03.

Model: gpt-5.4-mini Generated: 2026-06-23 19:07 UTC Revised: 2026-08-02 07:02 UTC Confidence: 0.95 12 comments
Chronology
  1. CFCA_Global_RSA_ROOT_G2 and its three intermediate CA certificates were issued.
  2. A CPR email was sent to c**********i@cfca.com.cn.
  3. A CPR was submitted through the web form after OCSPWatch detected unauthorized responses.
  4. CFCA deployed and verified OCSP service for all three intermediate CA certificates.
  5. CFCA posted a closure report requesting closure of the incident report.
Thread Activity
  1. China Financial Certification Authority (CFCA) — Opened the bug with a preliminary incident report describing unauthorized OCSP responses for the three intermediate CA certificates.
  2. Community commenter — Said the issue had been reported to c**********i@cfca.com.cn and noted the same email address on the CPR page.
  3. China Financial Certification Authority (CFCA) — Said CFCA searched the mailbox and found no matching email, and suggested the message may not have reached the server.
  4. Community commenter — Objected to CFCA’s speculative delivery explanation and said both the web form and email fallback had failed.
  5. China Financial Certification Authority (CFCA) — Posted the full incident report, including the OCSP deployment date and the incident timeline.
  6. China Financial Certification Authority (CFCA) — Corrected the earlier mailbox-search claim, withdrew the delivery speculation, and said the email was missed because of keyword-only monitoring.
  7. China Financial Certification Authority (CFCA) — Updated the action items, removed some CPR-mailbox items from this bug, and said they would be tracked in Bug #2054464.
  8. China Financial Certification Authority (CFCA) — Said there were no further updates yet.
  9. China Financial Certification Authority (CFCA) — Posted a closure report stating that the OCSP issue was remediated and all action items in this bug were complete.
  10. CCADB representative — Issued a final call for comments or questions and said the bug would be closed around 2026-08-03.
Participants
China Financial Certification Authority (CFCA) Community commenter CCADB representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#2054464 ASSIGNED Incident Self Reported Incident Problem Reporting Failure Remediation Tracking Opened 2026-07-13 Still Open · 90% similar
CFCA: Delayed response to CPR-related email related with bug 2049179
#2048995 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Problem Reporting Failure Opened 2026-06-19 · Closed 2026-07-30 · 89% similar
eMudhra emSign PKI Services: OCSP Responder Returned "Unauthorized" for Some Pecertificates
#2058920 ASSIGNED Ca Certificate Compliance Problem Reporting Failure Incident Externally Reported Incident Opened 2026-07-29 Still Open · 86% similar
CFCA: Delayed response to CPR related with bug 2058918
#2050274 ASSIGNED Ca Certificate Compliance Incident Ccadb Disclosure Issue Policy Document Issue Opened 2026-06-24 Still Open · 80% similar
FNMT: Delay in incident disclosure reporting for Bug 2049012
#2047952 ASSIGNED Ca Certificate Compliance Externally Reported Incident Problem Reporting Failure Ct Logging Issue Opened 2026-06-16 Still Open · 79% similar
KIR: OCSP responder does not return status for precertificate
#2047579 RESOLVED Ca Documents Audit Finding Policy Document Issue Information Request Opened 2026-06-15 · Closed 2026-07-27 · 79% similar
ANF AC: 2026 Audit Report Finding 1 out of 3
#2032482 RESOLVED Ca Certificate Compliance Incident Certificate Misissuance Problem Reporting Failure Opened 2026-04-16 · Closed 2026-07-30 · 79% similar
OATI: Misissuance detected by PKIMetal
#2032468 ASSIGNED Ca Certificate Compliance Externally Reported Incident Certificate Misissuance Policy Document Issue Opened 2026-04-16 Still Open · 77% similar
VISA: Misissuance detected by PKIMetal

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action