← Taiwan-CA Inc. (TWCA) cases
Bugzilla #1848306
Certificate Misissuance
TWCA: CA certificate without EKU
RESOLVED
FIXED
Taiwan-CA Inc. (TWCA)
AI Summary
Taiwan-CA Inc. (TWCA) identified a compliance issue with a CA certificate that was issued without the required extended key usage (EKU) extension. This oversight was discovered during an investigation prompted by a separate incident report. TWCA took immediate action to revoke the misissued certificate within the required timeframe and has since revised their standard operating procedures to prevent future occurrences. The CA certificate was revoked on August 17, 2023, and TWCA has ceased issuing certificates under the affected CA certificate.
Chronology
- TWCA became aware of the compliance issue.
- The CA certificate was revoked.
- TWCA completed checklists for CA lifecycle operations.
Participants
Hao-Chun Li
Ben Wilson
External References
Similar Local Cases
Asseco DS / Certum: S/MIME certificates with error in subjectAlternativeName
certSIGN: Subscriber precertificate without Certificate Policies
SwissSign: Mis-Issuance of S/MIME certificates
SwissSign: LDAP URL still in CRL distribution point (CDP)
DigiCert / Inteso San Paulo: Double dot characters
e-commerce monitoring gmbh: certificate issued with two pre-certificates
Sectigo: Incorrect inclusion of DBA name
Digicert: Failure to include CPS URI in 1 certificate