← Taiwan-CA Inc. (TWCA) cases
Bugzilla #1884568
Certificate Problem Report
TWCA: Revocation delay for EV TLS certificates with invalid subject attribute order
RESOLVED
FIXED
Taiwan-CA Inc. (TWCA)
AI Summary
TWCA mis-issued 90 EV TLS certificates that did not conform to the required subject attribute order. While all affected certificates were supposed to be revoked within five days, 13 certificates were not revoked on time due to customer requests for delays, as they were critical for banking applications. The CA has since completed the revocation of all affected certificates and has committed to stricter policies regarding timely revocation in the future.
Chronology
- BR for TLS 2.0.0 became effective.
- Email reporting the issue received.
- Compliance team confirmed the issue and started investigation.
- Revocation of certificates completed.
- Report closure summary provided.
Participants
Hao-Chun Li
Chris Clements
Tim Callan
External References
Similar Local Cases
TWCA: Revocation delay for TLS certificates with non-critical basicConstraints
TWCA: TLS EV certificates with invalid subject attribute order
TWCA: TLS certificates with non-critical basicConstraints
TWCA: "unknown" OCSP response for issued certificates
TWCA: Undisclosed CA
NETLOCK: SSL certificates with OU field - revocation delay
Telia: Delayed revocation of seven (7) certificates related to incident 1896108
TWCA: CA Certificate not published in DER Encoded Format