Google security team has discovered and blocked fraudulent digital certificates issued for several Google domains by a Chinese CA. The investigation revealed that a Chinese certificate authority was using an intermediate CA, MCS Holdings, that issued the bogus Google digital certificates. The private key was installed on a man-in-the-middle proxy, a network equipment used to eavesdrop secure connections by impersonating the intended destination for surveillance purpose. Google contacted officials at CNNIC, the Chinese registrar who authorized the intermediate CA and confirmed MCS issues certificates for domains that it registered.”]
Source: http://securityaffairs.co/wordpress/35253/digital-id/bogus-google-digital-certificates.html

