← China Financial Certification Authority (CFCA) cases
Bugzilla #1532429
Certificate Problem Report
CFCA: Invalid TLD in SAN
RESOLVED
FIXED
China Financial Certification Authority (CFCA)
AI Summary
The China Financial Certification Authority (CFCA) addressed an issue regarding a certificate with an invalid domain in the Subject Alternative Name (SAN) field. This problem was identified through community reports, and CFCA confirmed that the certificate had not been deployed in production and was revoked on March 1, 2019. They implemented a fix on February 27, 2019, and have since updated their processes to prevent similar issues, including the introduction of a hard fail detection mechanism and enhanced employee training.
Chronology
- CFCA implemented a fix for the invalid SAN issue.
- CFCA revoked the problematic certificate.
- All questions were answered and remediation was confirmed as completed.
Participants
Wayne Thayer
Jonathan Sun
Ryan Sleevi
Oliver
External References
Similar Local Cases
CFCA: invalid dnsNames
CFCA: Wrong SerialNumber encoding
CFCA: Internal iPAddress in certificate
CFCA: O > 64 characters
SwissSign: CP/CPS certificate profile issue
QuoVadis: N/A in EV serialNumber field
SECOM: certificate for which “L” and “ST” not set
PKIoverheid: KPN Insufficient Serial Number Entropy