← Taiwan-CA Inc. (TWCA) cases
Bugzilla #1848306 Ca Certificate Compliance Certificate Misissuance Remediation Tracking

TWCA: CA certificate without EKU

RESOLVED FIXED Taiwan-CA Inc. (TWCA)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case describes an incident involving a TWCA CA certificate that was issued without the extKeyUsage (EKU) extension. TWCA said it discovered the problem during investigation of another incident (Bug 1848240) and determined the CA certificate was not compliant with the Baseline Requirements for TLS Certificates and the Mozilla Root Store Policy. TWCA reported that it had planned to replace an expiring TLS-issuing CA certificate, but the profile used referenced a previous CA certificate that did not include EKU, resulting in the new CA certificate being issued without EKU. After realizing the potential non-compliance, TWCA stopped using the new CA certificate and switched issuance back to the old CA certificate. TWCA decided to revoke the CA certificate and scheduled revocation for 2023-08-17, stating it was revoked at 2023-08-17 14:59 UTC+8. In later comments, TWCA stated it completed checklists covering CA lifecycle operations and that the checklists include requirements from CA/B Forum, Root Program policies, and its CP/CPS; Mozilla indicated it would close the matter on or about 2023-11-01 unless there were further concerns.

Model: gpt-5.4-nano Generated: 2026-06-13 20:51 UTC Revised: 2026-06-16 18:14 UTC Confidence: 0.86 9 comments
Chronology
  1. TWCA issued a TLS-issuing CA certificate without the extKeyUsage (EKU) extension.
  2. TWCA identified the CA certificate as potentially non-compliant and began investigation.
  3. TWCA stopped using the new CA certificate and switched issuance back to the old CA certificate.
  4. TWCA revoked the CA certificate.
  5. TWCA reported completion of checklists for CA lifecycle operations.
Thread Activity
  1. Taiwan-CA Inc. (TWCA) — TWCA reported that during investigation it found the CA certificate lacked the extKeyUsage extension and was not compliant with BR TLS and MRSP requirements.
  2. Taiwan-CA Inc. (TWCA) — TWCA stated it had received a Bugzilla notice about another issue and that it realized the CA certificate did not include EKU.
  3. Taiwan-CA Inc. (TWCA) — TWCA scheduled revocation of the CA certificate for 2023-08-17 and said it was revising its SOP for CA certificate issuance.
  4. Taiwan-CA Inc. (TWCA) — TWCA stated the CA certificate was revoked at 2023-08-17 14:59 UTC+8.
  5. Taiwan-CA Inc. (TWCA) — TWCA posted a final incident report describing the timeline, stating the certificate was revoked within the BR-required timeframe, and explaining how the mistake occurred.
  6. Mozilla representative — Mozilla asked TWCA to let them know when checklists were completed so the matter could be closed.
  7. Taiwan-CA Inc. (TWCA) — TWCA said the checklists were completed and described their scope across CA lifecycle operations and referenced policy sources.
  8. Taiwan-CA Inc. (TWCA) — TWCA corrected a typo in a prior comment reference.
  9. Mozilla representative — Mozilla said it would close the matter on or about 2023-11-01 unless there were comments or concerns.
Participants
Taiwan-CA Inc. (TWCA) Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1848240 RESOLVED Ca Certificate Compliance Incident Remediation Tracking Opened 2023-08-10 · Closed 2023-11-02 · 100% similar
TWCA: Undisclosed CA
#1793445 RESOLVED Ca Security Vulnerability Remediation Tracking Opened 2022-10-03 · Closed 2023-04-19 · 93% similar
TWCA: "unknown" OCSP response for issued certificates
#1738778 RESOLVED Ca Certificate Compliance Incident Remediation Tracking Opened 2021-11-01 · Closed 2023-02-22 · 88% similar
TWCA: Policy OID not set to indicate the assurance level to the issued certs
#1853783 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2023-09-18 · Closed 2025-03-20 · 81% similar
IdenTrust: S/MIME certificates issued in violation of New S/MIME Baseline Requirements v1.0
#1887096 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2024-03-22 · Closed 2024-09-06 · 81% similar
Chunghwa Telecom: Wrong Extended Key Usage setting by GTLSCA
#1740493 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-11-10 · Closed 2023-02-22 · 80% similar
Sectigo: Failure to block disallowed LDH labels in domain names
#1586795 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-10-07 · Closed 2023-02-22 · 80% similar
NetLock: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy
#1802916 RESOLVED Ca Certificate Compliance Certificate Misissuance Remediation Tracking Opened 2022-11-28 · Closed 2023-04-24 · 80% similar
Entrust: EV TLS Certificate incorrect jurisdiction

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action