← Chunghwa Telecom cases
Bugzilla #1532436 Ca Certificate Compliance Certificate Misissuance Closure Request

Chunghwa Telecom incident report for two test certificates with unregistered domain names

RESOLVED FIXED Chunghwa Telecom
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Chunghwa Telecom reported that it found two mis-issued test certificates containing unregistered FQDNs during an internal review of certificates in crt.sh. The first certificate was revoked shortly after discovery, and issuance was suspended while the CA performed an initial investigation. Chunghwa Telecom said the issue was caused by human error in the RAO process, and it introduced additional controls including two-stage manual verification and automated FQDN checking. The CA later said it implemented further automated validation methods for domain checks and updated Mozilla regularly on deployment progress. The bug was ultimately resolved as FIXED.

Model: gpt-5.4-mini Generated: 2026-06-13 18:05 UTC Revised: 2026-06-16 18:02 UTC Confidence: 0.97 57 comments
Chronology
  1. First problematic certificate was issued with an unregistered FQDN.
  2. Second problematic certificate was issued with an unregistered FQDN.
  3. Chunghwa Telecom discovered the mis-issued certificates, revoked one, and suspended issuance during investigation.
  4. Automatic FQDN checking was implemented and enforced in Public CA.
  5. Automatic domain-name validation functionality was reported as going live.
  6. 3.2.2.4.2 was reported as having gone live.
Thread Activity
  1. Fastly representative — Wayne Thayer opened the bug with Chunghwa Telecom's incident report describing two mis-issued certificates with unregistered domain names.
  2. Cht representative — Chunghwa Telecom said automatic FQDN checking had been implemented and enforced on March 15.
  3. Cht representative — Chunghwa Telecom said it had implemented a scheduling program to scan issued certificates and had revoked certificates with inaccurate FQDNs caused by domain ownership changes.
  4. Fastly representative — Wayne Thayer asked how the RAO could issue the certificates without domain control validation and whether both domain existence and control could be checked automatically.
  5. Cht representative — Chunghwa Telecom said the two mis-issued certificates were OV certificates and that it had asked its vendor to add BR validation methods for authority checks.
  6. Cht representative — Chunghwa Telecom said its vendor would add additional validation methods and estimated the automatic domain-name check would go live around February 18, 2020.
  7. Cht representative — Chunghwa Telecom apologized for not replying regularly and promised weekly updates.
  8. Cht representative — Chunghwa Telecom said the changes had gone live and explained that WHOIS protocol decoding issues affected Chinese company names.
  9. Cht representative — Chunghwa Telecom said it supported several validation methods, with 3.2.2.4.2 still under development, and planned additional methods 3.2.2.4.13 and 3.2.2.4.14.
  10. Cht representative — Chunghwa Telecom said 3.2.2.4.2 had gone live.
  11. Cht representative — Chunghwa Telecom summarized the incident, said it had informed the auditor, and stated that the issuance of unregistered FQDNs could no longer occur.
Participants
Fastly representative Cht representative Community commenter Mozilla representative
Similar Local Cases
#1887096 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2024-03-22 · Closed 2024-09-06 · 99% similar
Chunghwa Telecom: Wrong Extended Key Usage setting by GTLSCA
#1627346 RESOLVED Ca Certificate Compliance Self Reported Incident Certificate Misissuance Delayed Revocation Opened 2020-04-03 · Closed 2023-02-22 · 96% similar
Entrust: S/MIME Certificate Issued with Incorrect Policy OID
#1559765 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-06-17 · Closed 2023-02-22 · 95% similar
Izenpe: Multiple invalid EV certificates issued
#1586795 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-10-07 · Closed 2023-02-22 · 94% similar
NetLock: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy
#1575022 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2019-08-19 · Closed 2023-02-22 · 93% similar
Sectigo: EV SSL Certificates with incorrect subject details.
#1951415 RESOLVED Certificate Misissuance Delayed Revocation Opened 2025-03-03 · Closed 2025-05-08 · 90% similar
Chunghwa Telecom: Failure to check restrictive CAA record during Migration
#1409766 RESOLVED Ca Certificate Compliance Self Reported Incident Certificate Misissuance Opened 2017-10-18 · Closed 2023-02-22 · 89% similar
Asseco DS / Certum: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record
#1716123 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-06-12 · Closed 2024-05-25 · 88% similar
e-commerce monitoring GmbH: CN domain not in SAN

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action