Discussion:
Second Discussion of CFCA Root Inclusion Request
Kathleen Wilson
2015-01-20 20:25:54 UTC
Permalink
China Financial Certification Authority (CFCA) has applied to include
the “CFCA EV ROOT” root certificate, turn on the websites trust bit, and
enable EV treatment.
The first discussion resulted in CA action items, which have been
completed.
https://groups.google.com/d/msg/mozilla.dev.security.policy/2G6KuAT9Ekk/GyakphSLS5EJ
https://bugzilla.mozilla.org/show_bug.cgi?id=926029#c26
For your convenience, and because the request has been changed to be
just for the EV root, I will re-summarize the request below.
CFCA is a national authority of security authentication approved by the
People’s Bank of China and state information security administration.
CFCA is a critical national infrastructure of financial information
security and one of the first certification service suppliers granted a
certification service license after the release of the Electronic
Signature Law of the People’s Republic of China. There are more than 200
Chinese banks that are using CFCA’s certificates to ensure the security
of online banking trade.
https://bugzilla.mozilla.org/show_bug.cgi?id=926029
http://www.mozilla.org/en-US/about/governance/policies/security-group/certs/pending/
https://bugzilla.mozilla.org/attachment.cgi?id=8545426
* The primary documents are the CPS and CP, which are provided in
Chinese, and the CPS has been translated into English.
Document repository: http://www.cfca.com.cn/us/us-12.htm
CPS (Chinese) http://www.cfca.com.cn/file/qqfwq-cps.zip
CP (Chinese): http://www.cfca.com.cn/file/qqfwq-cp.zip
CPS (English): http://www.cfca.com.cn/file/CFCA-1403-CPS-en.rar
* CA Hierarchy: The “CFCA EV ROOT” root has one internally-operated
subordinate CA, “CFCA EV OCA”, which issues EV SSL certificates.
* This request is to turn on the websites trust bit for the “CFCA EV
ROOT” root certificate, and enable EV treatment.
All,

Does anyone have questions or comments about CFCA's request for root
inclusion and EV treatment?

Thanks,
Kathleen
Erwann Abalea
2015-01-22 16:20:31 UTC
Permalink
China Financial Certification Authority (CFCA) has applied to include
the "CFCA EV ROOT" root certificate, turn on the websites trust bit, and
enable EV treatment.
[...]
* Root Cert: https://bugzilla.mozilla.org/attachment.cgi?id=8356494
* Test Website: https://pub.cebnet.com.cn
* OCSP
http://ocsp.cfca.com.cn/ocsp/
CPS 4.8.9: The maximum validity period for OCSP response does not exceed
7 days.
Sorry for the delay.

Getting the CRL issued by "CFCA EV ROOT" shows 2 revoked certificates (serial numbers 0x844543D3B8 and 0xE6A7F45CF7).
When requesting the OCSP for the status of these serial numbers, the OCSP responder replies with an "unknown" status.
c***@gmail.com
2015-01-23 09:00:01 UTC
Permalink
在 2015年1月23日星期五 UTC+8上午12:20:38,Erwann Abalea写道:
Post by Erwann Abalea
China Financial Certification Authority (CFCA) has applied to include
the "CFCA EV ROOT" root certificate, turn on the websites trust bit, and
enable EV treatment.
[...]
* Root Cert: https://bugzilla.mozilla.org/attachment.cgi?id=8356494
* Test Website: https://pub.cebnet.com.cn
* OCSP
http://ocsp.cfca.com.cn/ocsp/
CPS 4.8.9: The maximum validity period for OCSP response does not exceed
7 days.
Sorry for the delay.
Getting the CRL issued by "CFCA EV ROOT" shows 2 revoked certificates (serial numbers 0x844543D3B8 and 0xE6A7F45CF7).
When requesting the OCSP for the status of these serial numbers, the OCSP responder replies with an "unknown" status.
Erwann, Thanks for your review.

We checked the issue you mentioned, it appears that the 2 certificate with SN 0x844543D3B8 and 0xE6A7F45CF7 are OCSP signing certificates we replaced in 2014 in order to conform Baseline Requirement.

The problem is resolved by now, OCSP responses for 0x844543D3B8 and 0xE6A7F45CF7 are revoked instead of unknown.

Ocsp signing certificates's revoke status in OCSP system use to be offline for EV OCA level.
These certificates can't issue any certificates or be used as website certificates.

Now we updated the model, once there is any changes take place in EV OCA level, including issuance of new (EV OCA level)certificates and certificates revoke/replace(in EV OCA level) , the database of OCSP service for EV OCA level will update.

So this problem won't happen again.
In addition, this problem do not affect our current subscriber/user.
Kathleen Wilson
2015-01-27 21:24:46 UTC
Permalink
Post by Kathleen Wilson
China Financial Certification Authority (CFCA) has applied to include
the “CFCA EV ROOT” root certificate, turn on the websites trust bit, and
enable EV treatment.
The first discussion resulted in CA action items, which have been
completed.
https://groups.google.com/d/msg/mozilla.dev.security.policy/2G6KuAT9Ekk/GyakphSLS5EJ
https://bugzilla.mozilla.org/show_bug.cgi?id=926029#c26
For your convenience, and because the request has been changed to be
just for the EV root, I will re-summarize the request below.
CFCA is a national authority of security authentication approved by the
People’s Bank of China and state information security administration.
CFCA is a critical national infrastructure of financial information
security and one of the first certification service suppliers granted a
certification service license after the release of the Electronic
Signature Law of the People’s Republic of China. There are more than 200
Chinese banks that are using CFCA’s certificates to ensure the security
of online banking trade.
https://bugzilla.mozilla.org/show_bug.cgi?id=926029
http://www.mozilla.org/en-US/about/governance/policies/security-group/certs/pending/
https://bugzilla.mozilla.org/attachment.cgi?id=8545426
* The primary documents are the CPS and CP, which are provided in
Chinese, and the CPS has been translated into English.
Document repository: http://www.cfca.com.cn/us/us-12.htm
CPS (Chinese) http://www.cfca.com.cn/file/qqfwq-cps.zip
CP (Chinese): http://www.cfca.com.cn/file/qqfwq-cp.zip
CPS (English): http://www.cfca.com.cn/file/CFCA-1403-CPS-en.rar
* CA Hierarchy: The “CFCA EV ROOT” root has one internally-operated
subordinate CA, “CFCA EV OCA”, which issues EV SSL certificates.
* This request is to turn on the websites trust bit for the “CFCA EV
ROOT” root certificate, and enable EV treatment.
All,
Does anyone have questions or comments about CFCA's request for root
inclusion and EV treatment?
Thanks,
Kathleen
Thanks, Erwann, for reviewing and commenting on this request again.

I believe that all of the questions and concerns that were raised during
the first discussion and this discussion have been resolved.

If there are no further questions or comments about CFCA's root
inclusion request, then I will close this discussion and recommend
approval in the bug.

Thanks,
Kathleen
Kathleen Wilson
2015-02-04 18:46:49 UTC
Permalink
Thanks to all of you who reviewed and commented on this request from
CFCA to include the “CFCA EV ROOT” root certificate, turn on the
websites trust bit, and enable EV treatment.

I am closing this discussion, and I will recommend approval in the bug.

https://bugzilla.mozilla.org/show_bug.cgi?id=926029

Any further follow-up on this request should be added directly to the bug.

Thanks,
Kathleen

Loading...