In this case both Head Office and Site A routers run VRF (and OSPF) although they are CE routers. So we must configure "capability vrf-lite" on them too. For your information, the capability vrf-lite command disables the DN-bit (down bit) and domain- tag checks in OSPF. Since the CE router acts as the PE router in VRF-lite, these checks should be disabled, because the PE routers advertise VPN routes with DN-bit set to the CE routers. If the CE routers receive routes with DN-bit set, it will discard them. Hence, the checks should be disabled.