cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Xcc Trust OV SSL CA Intermediate Certificate Fraud and Violation Risk

lolocoun
Making moves

1. Relevant Documents Referenced
CA/Browser Forum Baseline Requirements for the Issuance and Management of Publicly-Trusted Certificates, EV SSL Certificate Guidelines

2. Overview of the Issue
This submission reports severe non-compliant practices and consumer deception risks related to two intermediate CA certificates under Certum’s root trust chain:

Xcc Trust DV SSL CA
Xcc Trust OV SSL CA
These two intermediates have been operated by an unvetted third-party entity in China, resulting in widespread false identity verification for OV certificates, misleading geographic labeling, and fraudulent commercial promotion that violates CA/B Forum baseline requirements and undermines the trust of global TLS ecosystem users.

3. Verified Non-Compliant Facts
Severe OV Identity Verification Irregularities
The intermediate certificates have issued OV SSL certificates with falsified real-name organization information, including instances where Chinese government public institution domains were bound to incorrectly authenticated entity names that do not match the actual domain operator. This violates the mandatory identity validation clauses in CA/B Forum Baseline Requirements Section 3.2.

Misleading Country Attribute Marking
Though the two intermediate certificates are fully issued and controlled by Certum, a CA entity legally registered and operating in Poland, their countryName attribute is incorrectly marked as CN (China). This visible field directly misleads end users into mistaking them for domestically issued Chinese CA products.

Fraudulent Commercial Promotion
The actual operator behind the intermediates — a Chinese technology company and its subsidiary — has publicly misrepresented itself as a native Chinese CA manufacturer. It spread unsubstantiated rumors that mainstream international CAs including Sectigo and DigiCert would be removed from Chinese browser trust stores, while marketing Certum-issued Xcc Trust certificates as "100% domestic Chinese SSL certificates" to government agencies, public institutions and enterprise customers.

Inconsistent Product Specification Disclosure
The operator’s official product page https://www.zyyx.cn/ov_alone publishes technical parameters for these OV certificates that are completely inconsistent with Certum’s official public CPS and certificate profile specifications, constituting further misleading behavior for purchasers.
The OV SSL certificate related information published on this page contains the following content:

At present, a massive number of Chinese government departments and public institutions have been deceived into purchasing these misrepresented products, which has caused serious damage to the credibility of the global public TLS trust system.

4. Formal Rectification Requests to CA/Browser Forum and Certum
Immediate Compliance Audit
Require Certum to launch an immediate full audit of all certificates issued through Xcc Trust DV SSL CA and Xcc Trust OV SSL CA, and suspend new certificate issuance through these two intermediates until all non-conformities are fully resolved.

Correct Misleading Certificate Attributes
Mandate Certum to revise the countryName field of these two intermediate certificates to accurately reflect Certum’s actual country of origin (PL, Poland), ensuring the geographic origin information is clearly visible to all users through standard certificate viewers.

Standardize Public Information Disclosure
Require Certum to publicly clarify on its official website that these two Xcc Trust intermediate certificates are Certum-issued products originating from Poland, and prohibit any third-party operator from using these intermediates to make false "domestic CA" marketing claims.

Improve Intermediate Certificate Lifecycle Management
Advise the CA/Browser Forum to add clearer mandatory clauses in the updated Baseline Requirements, requiring all member CAs to strictly audit and continuously monitor third-party operated intermediate certificates under their trust chain, to prevent similar "foreign root + misrepresented intermediate" impersonation incidents from recurring globally.

5. Impact Statement
This type of practice — using a globally trusted foreign root certificate with a misleadingly labeled intermediate to impersonate a local domestic CA — is rapidly spreading in the Chinese market. It not only infringes the legitimate rights and interests of hundreds of thousands of government and enterprise users, but also erodes the unified global trust foundation that the CA/Browser Forum has long maintained. Timely rectification of this case will set a critical precedent for safeguarding the openness, transparency and credibility of the worldwide public TLS ecosystem.

0 REPLIES 0