TWCA: CA certificate without EKU
This case describes an incident involving a TWCA CA certificate that was issued without the extKeyUsage (EKU) extension. TWCA said it discovered the problem during investigation of another incident (Bug 1848240) and determined the CA certificate was not compliant with the Baseline Requirements for TLS Certificates and the Mozilla Root Store Policy. TWCA reported that it had planned to replace an expiring TLS-issuing CA certificate, but the profile used referenced a previous CA certificate that did not include EKU, resulting in the new CA certificate being issued without EKU. After realizing the potential non-compliance, TWCA stopped using the new CA certificate and switched issuance back to the old CA certificate. TWCA decided to revoke the CA certificate and scheduled revocation for 2023-08-17, stating it was revoked at 2023-08-17 14:59 UTC+8. In later comments, TWCA stated it completed checklists covering CA lifecycle operations and that the checklists include requirements from CA/B Forum, Root Program policies, and its CP/CPS; Mozilla indicated it would close the matter on or about 2023-11-01 unless there were further concerns.
- TWCA issued a TLS-issuing CA certificate without the extKeyUsage (EKU) extension.
- TWCA identified the CA certificate as potentially non-compliant and began investigation.
- TWCA stopped using the new CA certificate and switched issuance back to the old CA certificate.
- TWCA revoked the CA certificate.
- TWCA reported completion of checklists for CA lifecycle operations.
- Taiwan-CA Inc. (TWCA) — TWCA reported that during investigation it found the CA certificate lacked the extKeyUsage extension and was not compliant with BR TLS and MRSP requirements.
- Taiwan-CA Inc. (TWCA) — TWCA stated it had received a Bugzilla notice about another issue and that it realized the CA certificate did not include EKU.
- Taiwan-CA Inc. (TWCA) — TWCA scheduled revocation of the CA certificate for 2023-08-17 and said it was revising its SOP for CA certificate issuance.
- Taiwan-CA Inc. (TWCA) — TWCA stated the CA certificate was revoked at 2023-08-17 14:59 UTC+8.
- Taiwan-CA Inc. (TWCA) — TWCA posted a final incident report describing the timeline, stating the certificate was revoked within the BR-required timeframe, and explaining how the mistake occurred.
- Mozilla representative — Mozilla asked TWCA to let them know when checklists were completed so the matter could be closed.
- Taiwan-CA Inc. (TWCA) — TWCA said the checklists were completed and described their scope across CA lifecycle operations and referenced policy sources.
- Taiwan-CA Inc. (TWCA) — TWCA corrected a typo in a prior comment reference.
- Mozilla representative — Mozilla said it would close the matter on or about 2023-11-01 unless there were comments or concerns.