Chunghwa Telecom: ALV failures on intermediate certificates
This case was filed because Chunghwa Telecom responded to Action 5 of Mozilla's January 2020 CA Communication survey stating it had no audit issues with its intermediate certificates identified by CCADB, but Audit Letter Validation (ALV) reported problems that the CA needed to investigate and resolve. The reporter listed multiple intermediate certificates where ALV results were FAIL. The CA owner, r**********y@cht.com.tw, stated that they investigated and resolved the ALV issues for the intermediate certificates. For audit statements issued in 2019, the CA said it would add comments to the Standard Audit ALV Comments or BR Audit ALV Comments fields noting that the SHA-256 fingerprint was listed but had a formatting problem to be fixed in the next annual audit statement. For new certificates issued after the last annual audit, the CA said it would add comments requesting the auditor provide an updated audit statement that follows the formatting requirements for SHA-256 fingerprints in July or August 2020. The bug is marked RESOLVED with resolution FIXED.
- Bug opened after ALV reported FAIL results for multiple Chunghwa Telecom intermediate certificates despite a survey response indicating no audit issues.
- CA owner reported remediation steps for ALV failures by updating ALV comment fields and planning corrected audit statement formatting.
- Mozilla representative — Filed the bug citing ALV FAIL results for several Chunghwa Telecom intermediate certificates and requested the CA investigate and resolve per the ALV standard.
- Cht representative — Reported that the CA investigated and resolved the ALV issues by adding ALV comment-field notes about SHA-256 fingerprint formatting problems and requesting updated audit statements for new certificates.