← Taiwan-CA Inc. (TWCA) cases
Bugzilla #1883620
Certificate Problem Report
TWCA: TLS EV certificates with invalid subject attribute order
RESOLVED
FIXED
Taiwan-CA Inc. (TWCA)
AI Summary
TWCA identified an issue with 90 EV TLS certificates that were issued with a nonconforming subject attribute order, violating BR Section 7.1.4.2. Following the report of this potential mis-issuance on March 4, 2024, TWCA halted the issuance of EV TLS certificates and patched their issuing system. They have since revoked or expired 77 of the affected certificates and are working on revoking the remaining 13 by March 23, 2024. The incident highlighted the need for improved monitoring and compliance checks within their certificate issuance process.
Chronology
- TLS BR 2.0.0 became effective.
- Email reporting the issue received.
- Compliance team confirmed the issue and stopped issuance of EV TLS certificates.
- All affected certificates identified.
- 77 affected certificates revoked or expired.
- All affected certificates in this incident have been revoked.
Participants
Hao-Chun Li
hcli@twca.com.tw
chtsai@twca.com.tw
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
TWCA: Revocation delay for TLS certificates with non-critical basicConstraints
TWCA: TLS certificates with non-critical basicConstraints
TWCA: Revocation delay for EV TLS certificates with invalid subject attribute order
TWCA: "unknown" OCSP response for issued certificates
TWCA: Undisclosed CA
TWCA: CA Certificate not published in DER Encoded Format
certSIGN: Certificates with incorrect Subject attribute order
Buypass: TLS certificates with incorrect Subject attribute order