← Chunghwa Telecom cases
Bugzilla #1614444 Ca Certificate Compliance Audit Finding

Chunghwa Telecom: ALV failures on intermediate certificates

RESOLVED FIXED Chunghwa Telecom
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case was filed because Chunghwa Telecom responded to Action 5 of Mozilla's January 2020 CA Communication survey stating it had no audit issues with its intermediate certificates identified by CCADB, but Audit Letter Validation (ALV) reported problems that the CA needed to investigate and resolve. The reporter listed multiple intermediate certificates where ALV results were FAIL. The CA owner, r**********y@cht.com.tw, stated that they investigated and resolved the ALV issues for the intermediate certificates. For audit statements issued in 2019, the CA said it would add comments to the Standard Audit ALV Comments or BR Audit ALV Comments fields noting that the SHA-256 fingerprint was listed but had a formatting problem to be fixed in the next annual audit statement. For new certificates issued after the last annual audit, the CA said it would add comments requesting the auditor provide an updated audit statement that follows the formatting requirements for SHA-256 fingerprints in July or August 2020. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:18 UTC Revised: 2026-06-16 18:03 UTC Confidence: 0.86 2 comments
Chronology
  1. Bug opened after ALV reported FAIL results for multiple Chunghwa Telecom intermediate certificates despite a survey response indicating no audit issues.
  2. CA owner reported remediation steps for ALV failures by updating ALV comment fields and planning corrected audit statement formatting.
Thread Activity
  1. Mozilla representative — Filed the bug citing ALV FAIL results for several Chunghwa Telecom intermediate certificates and requested the CA investigate and resolve per the ALV standard.
  2. Cht representative — Reported that the CA investigated and resolved the ALV issues by adding ALV comment-field notes about SHA-256 fingerprint formatting problems and requesting updated audit statements for new certificates.
Participants
Mozilla representative Cht representative
Similar Local Cases
#1614450 RESOLVED Audit Finding Opened 2020-02-10 · Closed 2022-11-14 · 73% similar
SwissSign: Audit Letter Validation failures on intermediate certificates
#1614821 RESOLVED Audit Finding Opened 2020-02-11 · Closed 2024-06-30 · 70% similar
Dhimyotis / Certigna: Intermediate CAs missing audits
#835538 RESOLVED Ca Documents Audit Finding Opened 2013-01-28 · Closed 2022-11-14 · 69% similar
TURKTRUST audit regarding change management procedures and controls
#2009045 RESOLVED Self Reported Incident Audit Finding Opened 2026-01-07 · Closed 2026-02-19 · 68% similar
Chunghwa Telecom: Delayed disclosure to Bug 2008788 GTLSCA Audit Incident Report #2 - Domain validation records without the TLS BR version
#2009046 RESOLVED Self Reported Incident Audit Finding Opened 2026-01-07 · Closed 2026-02-19 · 68% similar
Chunghwa Telecom: Delayed disclosure to Bug 2008799 GTLSCA Audit Incident Report #3 - Missing vulnerability scan
#2009048 RESOLVED Self Reported Incident Audit Finding Opened 2026-01-07 · Closed 2026-02-19 · 68% similar
Chunghwa Telecom: Delayed disclosure to Bug 2008803 GTLSCA Audit Incident Report #4 - Missing evaluation for third parties
#1313445 RESOLVED Ca Documents Audit Finding Opened 2016-10-27 · Closed 2022-12-08 · 67% similar
Audit info for SECOM
#1549862 RESOLVED Ca Documents Audit Finding Opened 2019-05-07 · Closed 2023-02-22 · 67% similar
Entrust: Outdated audit statement for intermediate cert

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action