← Taiwan-CA Inc. (TWCA) cases
Bugzilla #1848240 Ca Certificate Compliance Incident Remediation Tracking

TWCA: Undisclosed CA

RESOLVED FIXED Taiwan-CA Inc. (TWCA)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Mozilla’s Root Store Policy requires CCADB disclosure of new subordinate CAs within one week of certificate creation. In this case, Mozilla identified that a subordinate CA certificate for “TWCA Secure SSL Certification Authority” (new CA certificate not-before 2023-04-13) had not been disclosed in CCADB within the required timeframe. TWCA confirmed that the certificate was a new generation of the same CA and stated that it had uploaded the CA certificate to CCADB and began investigating after receiving notice from Bugzilla. TWCA also reported that it switched TLS certificate issuance to the new CA key and certificate on 2023-08-10, then switched issuance back to the old CA certificate and stopped using the new CA certificate on 2023-08-11. TWCA later revoked the CA certificate on 2023-08-17 (referencing Bug 1848306) and stated it had stopped issuing certificates from the problematic CA certificate immediately. TWCA said it was revising its SOP to ensure CCADB disclosure is confirmed by compliance staff, and later reported that checklists for CA lifecycle operations had been completed. The bug was resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 20:51 UTC Revised: 2026-06-16 18:13 UTC Confidence: 0.90 7 comments
Chronology
  1. TWCA issued a new CA certificate for “TWCA Secure SSL Certification Authority” to replace the prior CA certificate.
  2. TWCA switched its TLS certificate issuance system to use the new CA key and certificate.
  3. TWCA uploaded the new CA certificate to CCADB and switched certificate issuance back to the old CA certificate, stopping use of the new CA certificate.
  4. TWCA revoked the CA certificate.
  5. TWCA reported that its CA lifecycle checklists had been completed.
Thread Activity
  1. Mozilla representative — Ben Wilson reported that a subordinate CA certificate appeared not to be disclosed in CCADB within one week of certificate creation and requested an Incident Report per MRSP.
  2. Taiwan-CA Inc. (TWCA) — Hao-Chun Li confirmed the certificate was the new generation of the TWCA Secure SSL Certification Authority, uploaded it to CCADB, and started investigating.
  3. Taiwan-CA Inc. (TWCA) — Hao-Chun Li submitted an Incident Report describing the timeline, stating issuance was stopped, and explaining the SOP/communication gaps and remediation steps.
  4. Taiwan-CA Inc. (TWCA) — Hao-Chun Li posted a Final Incident Report, including that the CA certificate was revoked on 2023-08-17 and that the report was being posted.
  5. Mozilla representative — Ben Wilson asked when TWCA’s checklists would be completed so the matter could be closed.
  6. Taiwan-CA Inc. (TWCA) — Hao-Chun Li stated the checklists had been completed and described their scope across CA lifecycle operations.
  7. Mozilla representative — Ben Wilson said he would close the matter on or about 2023-11-01 unless there were concerns.
Participants
Mozilla representative Taiwan-CA Inc. (TWCA)
Related Bugzilla IDs Mentioned
Similar Local Cases
#1848306 RESOLVED Ca Certificate Compliance Certificate Misissuance Remediation Tracking Opened 2023-08-11 · Closed 2023-11-02 · 100% similar
TWCA: CA certificate without EKU
#1793445 RESOLVED Ca Security Vulnerability Remediation Tracking Opened 2022-10-03 · Closed 2023-04-19 · 94% similar
TWCA: "unknown" OCSP response for issued certificates
#1738778 RESOLVED Ca Certificate Compliance Incident Remediation Tracking Opened 2021-11-01 · Closed 2023-02-22 · 89% similar
TWCA: Policy OID not set to indicate the assurance level to the issued certs
#1651026 RESOLVED Certificate Misissuance Incident Remediation Tracking Opened 2020-07-07 · Closed 2023-02-22 · 78% similar
Izenpe: certificate issued to internal domain
#1682270 RESOLVED Ca Certificate Compliance Incident Closure Request Opened 2020-12-14 · Closed 2026-06-12 · 78% similar
D-TRUST: Private Key Disclosed by Customer as Part of CSR
#1717795 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Opened 2021-06-23 · Closed 2023-02-22 · 78% similar
Firmaprofesional: 2021 Audit Report Finding 3 out of 3
#1593776 RESOLVED Ca Certificate Compliance Incident Opened 2019-11-04 · Closed 2023-02-22 · 77% similar
Sectigo: invalid subject:organizationalUnitName on DV certificates
#1597950 RESOLVED Ca Certificate Compliance Incident Opened 2019-11-20 · Closed 2023-02-22 · 77% similar
Sectigo: CCADB failed ALV - Ensured Root CA

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action