New issue
Advanced search Search tips

Issue 619362 link

Starred by 1 user

Issue metadata

Status: Fixed
Owner:
Closed: Dec 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 3
Type: Bug



Sign in to add a comment

Add CFCA root certificate and EV OID to Chrome "EV-Qualified" list.

Reported by apollo7...@gmail.com, Jun 12 2016

Issue description

Steps to reproduce the problem:
Access the test websites with latest Chrome with SSL connection.

What is the expected behavior?
Add CFCA root certificate to Chrome "EV-Qualified" list.

What went wrong? 
https connection is fine and green lock is displayed but no EV treatment.

Did this work before? No 

Chrome version: all version including the latest
OS Version: 6.1 (Windows 7, Windows 8, windows 10)
Flash Version: Shockwave Flash 21.0 r0

①
Friendly Name: CFCA EV ROOT
Cert Location: https://bugzilla.mozilla.org/attachment.cgi?id=8356494
SHA-1 Fingerprint: E2:B8:29:4B:55:84:AB:6B:58:C2:90:46:6C:AC:3F:B8:39:8F:84:83
Test URL: https://pub.cebnet.com.cn
EV Policy OID(s): 2.16.156.112554.3

②
Annual audits are performed by PricewaterhouseCoopers, according to the WebTrust criteria.
Standard Audit(Webtrust): https://cert.webtrust.org/SealFile?seal=1788&file=pdf
BR Audit: https://cert.webtrust.org/SealFile?seal=1787&file=pdf
EV Audit: https://cert.webtrust.org/SealFile?seal=1786&file=pdf

③
CA Document Repository: http://www.cfca.com.cn/us/us-12.htm
CPS: http://www.cfca.com.cn/file/CFCA_EV_ROOT_CPS_en_2016.6.zip
CRL URLs: 
http://crl.cfca.com.cn/evrca/RSA/crl1.crl
http://crl.cfca.com.cn/evoca/RSA/crl1.crl
OCSP URL: http://ocsp.cfca.com.cn/ocsp/

④
CFCA EV ROOT already included in Microsoft (May 2013).

http://social.technet.microsoft.com/wiki/contents/articles/19217.windows-and-windows-phone-8-ssl-root-certificate-program-may-2013.aspx

CFCA EV ROOT already included in Mozilla NSS and acuired EV Treatment in FireFox38(May 2015).
https://bugzilla.mozilla.org/show_bug.cgi?id=926029

CFCA EV ROOT already included in Android 6.0(Oct 2015).



 
please use 
https://www.erenepu.com/
as test url for now

Test URL: https://pub.cebnet.com.cn certificate is expired.

Labels: Te-NeedsFurtherTriage

Comment 3 by mmenke@chromium.org, Jun 16 2016

Components: Internals>Network>SSL>EV
Owner: awhalley@chromium.org
Status: Assigned (was: Unconfirmed)
Hello, Is there any progress on this issue? 
Components: Internals>Network>EV
Components: -Internals>Network>SSL>EV
Project Member

Comment 8 by bugdroid1@chromium.org, Dec 22 2016

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/93e404c51625c47621a67121d5c73a70251c9a35

commit 93e404c51625c47621a67121d5c73a70251c9a35
Author: awhalley <awhalley@chromium.org>
Date: Thu Dec 22 23:41:01 2016

Update EV metadata

For Amazon, CFCA, Entrust, LuxTrust, and OISTE WISeKey

BUG= 619362 , 442481 , 497605 , 655624 , 498163 

R=rsleevi@chromium.org

Review-Url: https://codereview.chromium.org/2593303002
Cr-Commit-Position: refs/heads/master@{#440545}

[modify] https://crrev.com/93e404c51625c47621a67121d5c73a70251c9a35/net/cert/ev_root_ca_metadata.cc

Status: Fixed (was: Assigned)

Sign in to add a comment