<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Xcc Trust OV SSL CA Intermediate Certificate Fraud and Violation Risk in Discussions</title>
    <link>https://connect.mozilla.org/t5/discussions/xcc-trust-ov-ssl-ca-intermediate-certificate-fraud-and-violation/m-p/136181#M55015</link>
    <description>&lt;P&gt;1. Relevant Documents Referenced&lt;BR /&gt;CA/Browser Forum Baseline Requirements for the Issuance and Management of Publicly-Trusted Certificates, EV SSL Certificate Guidelines&lt;/P&gt;&lt;P&gt;2. Overview of the Issue&lt;BR /&gt;This submission reports severe non-compliant practices and consumer deception risks related to two intermediate CA certificates under Certum’s root trust chain:&lt;/P&gt;&lt;P&gt;Xcc Trust DV SSL CA&lt;BR /&gt;Xcc Trust OV SSL CA&lt;BR /&gt;These two intermediates have been operated by an unvetted third-party entity in China, resulting in widespread false identity verification for OV certificates, misleading geographic labeling, and fraudulent commercial promotion that violates CA/B Forum baseline requirements and undermines the trust of global TLS ecosystem users.&lt;/P&gt;&lt;P&gt;3. Verified Non-Compliant Facts&lt;BR /&gt;Severe OV Identity Verification Irregularities&lt;BR /&gt;The intermediate certificates have issued OV SSL certificates with falsified real-name organization information, including instances where Chinese government public institution domains were bound to incorrectly authenticated entity names that do not match the actual domain operator. This violates the mandatory identity validation clauses in CA/B Forum Baseline Requirements Section 3.2.&lt;/P&gt;&lt;P&gt;Misleading Country Attribute Marking&lt;BR /&gt;Though the two intermediate certificates are fully issued and controlled by Certum, a CA entity legally registered and operating in Poland, their countryName attribute is incorrectly marked as CN (China). This visible field directly misleads end users into mistaking them for domestically issued Chinese CA products.&lt;/P&gt;&lt;P&gt;Fraudulent Commercial Promotion&lt;BR /&gt;The actual operator behind the intermediates — a Chinese technology company and its subsidiary — has publicly misrepresented itself as a native Chinese CA manufacturer. It spread unsubstantiated rumors that mainstream international CAs including Sectigo and DigiCert would be removed from Chinese browser trust stores, while marketing Certum-issued Xcc Trust certificates as "100% domestic Chinese SSL certificates" to government agencies, public institutions and enterprise customers.&lt;/P&gt;&lt;P&gt;Inconsistent Product Specification Disclosure&lt;BR /&gt;The operator’s official product page &lt;A href="https://www.zyyx.cn/ov_alone" target="_blank" rel="noopener"&gt;https://www.zyyx.cn/ov_alone&lt;/A&gt; publishes technical parameters for these OV certificates that are completely inconsistent with Certum’s official public CPS and certificate profile specifications, constituting further misleading behavior for purchasers.&lt;BR /&gt;The OV SSL certificate related information published on this page contains the following content:&lt;/P&gt;&lt;P&gt;At present, a massive number of Chinese government departments and public institutions have been deceived into purchasing these misrepresented products, which has caused serious damage to the credibility of the global public TLS trust system.&lt;/P&gt;&lt;P&gt;4. Formal Rectification Requests to CA/Browser Forum and Certum&lt;BR /&gt;Immediate Compliance Audit&lt;BR /&gt;Require Certum to launch an immediate full audit of all certificates issued through Xcc Trust DV SSL CA and Xcc Trust OV SSL CA, and suspend new certificate issuance through these two intermediates until all non-conformities are fully resolved.&lt;/P&gt;&lt;P&gt;Correct Misleading Certificate Attributes&lt;BR /&gt;Mandate Certum to revise the countryName field of these two intermediate certificates to accurately reflect Certum’s actual country of origin (PL, Poland), ensuring the geographic origin information is clearly visible to all users through standard certificate viewers.&lt;/P&gt;&lt;P&gt;Standardize Public Information Disclosure&lt;BR /&gt;Require Certum to publicly clarify on its official website that these two Xcc Trust intermediate certificates are Certum-issued products originating from Poland, and prohibit any third-party operator from using these intermediates to make false "domestic CA" marketing claims.&lt;/P&gt;&lt;P&gt;Improve Intermediate Certificate Lifecycle Management&lt;BR /&gt;Advise the CA/Browser Forum to add clearer mandatory clauses in the updated Baseline Requirements, requiring all member CAs to strictly audit and continuously monitor third-party operated intermediate certificates under their trust chain, to prevent similar "foreign root + misrepresented intermediate" impersonation incidents from recurring globally.&lt;/P&gt;&lt;P&gt;5. Impact Statement&lt;BR /&gt;This type of practice — using a globally trusted foreign root certificate with a misleadingly labeled intermediate to impersonate a local domestic CA — is rapidly spreading in the Chinese market. It not only infringes the legitimate rights and interests of hundreds of thousands of government and enterprise users, but also erodes the unified global trust foundation that the CA/Browser Forum has long maintained. Timely rectification of this case will set a critical precedent for safeguarding the openness, transparency and credibility of the worldwide public TLS ecosystem.&lt;/P&gt;</description>
    <pubDate>Thu, 27 Aug 2026 11:10:39 GMT</pubDate>
    <dc:creator>lolocoun</dc:creator>
    <dc:date>2026-08-27T11:10:39Z</dc:date>
    <item>
      <title>Xcc Trust OV SSL CA Intermediate Certificate Fraud and Violation Risk</title>
      <link>https://connect.mozilla.org/t5/discussions/xcc-trust-ov-ssl-ca-intermediate-certificate-fraud-and-violation/m-p/136181#M55015</link>
      <description>&lt;P&gt;1. Relevant Documents Referenced&lt;BR /&gt;CA/Browser Forum Baseline Requirements for the Issuance and Management of Publicly-Trusted Certificates, EV SSL Certificate Guidelines&lt;/P&gt;&lt;P&gt;2. Overview of the Issue&lt;BR /&gt;This submission reports severe non-compliant practices and consumer deception risks related to two intermediate CA certificates under Certum’s root trust chain:&lt;/P&gt;&lt;P&gt;Xcc Trust DV SSL CA&lt;BR /&gt;Xcc Trust OV SSL CA&lt;BR /&gt;These two intermediates have been operated by an unvetted third-party entity in China, resulting in widespread false identity verification for OV certificates, misleading geographic labeling, and fraudulent commercial promotion that violates CA/B Forum baseline requirements and undermines the trust of global TLS ecosystem users.&lt;/P&gt;&lt;P&gt;3. Verified Non-Compliant Facts&lt;BR /&gt;Severe OV Identity Verification Irregularities&lt;BR /&gt;The intermediate certificates have issued OV SSL certificates with falsified real-name organization information, including instances where Chinese government public institution domains were bound to incorrectly authenticated entity names that do not match the actual domain operator. This violates the mandatory identity validation clauses in CA/B Forum Baseline Requirements Section 3.2.&lt;/P&gt;&lt;P&gt;Misleading Country Attribute Marking&lt;BR /&gt;Though the two intermediate certificates are fully issued and controlled by Certum, a CA entity legally registered and operating in Poland, their countryName attribute is incorrectly marked as CN (China). This visible field directly misleads end users into mistaking them for domestically issued Chinese CA products.&lt;/P&gt;&lt;P&gt;Fraudulent Commercial Promotion&lt;BR /&gt;The actual operator behind the intermediates — a Chinese technology company and its subsidiary — has publicly misrepresented itself as a native Chinese CA manufacturer. It spread unsubstantiated rumors that mainstream international CAs including Sectigo and DigiCert would be removed from Chinese browser trust stores, while marketing Certum-issued Xcc Trust certificates as "100% domestic Chinese SSL certificates" to government agencies, public institutions and enterprise customers.&lt;/P&gt;&lt;P&gt;Inconsistent Product Specification Disclosure&lt;BR /&gt;The operator’s official product page &lt;A href="https://www.zyyx.cn/ov_alone" target="_blank" rel="noopener"&gt;https://www.zyyx.cn/ov_alone&lt;/A&gt; publishes technical parameters for these OV certificates that are completely inconsistent with Certum’s official public CPS and certificate profile specifications, constituting further misleading behavior for purchasers.&lt;BR /&gt;The OV SSL certificate related information published on this page contains the following content:&lt;/P&gt;&lt;P&gt;At present, a massive number of Chinese government departments and public institutions have been deceived into purchasing these misrepresented products, which has caused serious damage to the credibility of the global public TLS trust system.&lt;/P&gt;&lt;P&gt;4. Formal Rectification Requests to CA/Browser Forum and Certum&lt;BR /&gt;Immediate Compliance Audit&lt;BR /&gt;Require Certum to launch an immediate full audit of all certificates issued through Xcc Trust DV SSL CA and Xcc Trust OV SSL CA, and suspend new certificate issuance through these two intermediates until all non-conformities are fully resolved.&lt;/P&gt;&lt;P&gt;Correct Misleading Certificate Attributes&lt;BR /&gt;Mandate Certum to revise the countryName field of these two intermediate certificates to accurately reflect Certum’s actual country of origin (PL, Poland), ensuring the geographic origin information is clearly visible to all users through standard certificate viewers.&lt;/P&gt;&lt;P&gt;Standardize Public Information Disclosure&lt;BR /&gt;Require Certum to publicly clarify on its official website that these two Xcc Trust intermediate certificates are Certum-issued products originating from Poland, and prohibit any third-party operator from using these intermediates to make false "domestic CA" marketing claims.&lt;/P&gt;&lt;P&gt;Improve Intermediate Certificate Lifecycle Management&lt;BR /&gt;Advise the CA/Browser Forum to add clearer mandatory clauses in the updated Baseline Requirements, requiring all member CAs to strictly audit and continuously monitor third-party operated intermediate certificates under their trust chain, to prevent similar "foreign root + misrepresented intermediate" impersonation incidents from recurring globally.&lt;/P&gt;&lt;P&gt;5. Impact Statement&lt;BR /&gt;This type of practice — using a globally trusted foreign root certificate with a misleadingly labeled intermediate to impersonate a local domestic CA — is rapidly spreading in the Chinese market. It not only infringes the legitimate rights and interests of hundreds of thousands of government and enterprise users, but also erodes the unified global trust foundation that the CA/Browser Forum has long maintained. Timely rectification of this case will set a critical precedent for safeguarding the openness, transparency and credibility of the worldwide public TLS ecosystem.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Aug 2026 11:10:39 GMT</pubDate>
      <guid>https://connect.mozilla.org/t5/discussions/xcc-trust-ov-ssl-ca-intermediate-certificate-fraud-and-violation/m-p/136181#M55015</guid>
      <dc:creator>lolocoun</dc:creator>
      <dc:date>2026-08-27T11:10:39Z</dc:date>
    </item>
  </channel>
</rss>

