← Taiwan-CA Inc. (TWCA) cases
Bugzilla #1885132
Certificate Problem Report
TWCA: TLS certificates with non-critical basicConstraints
RESOLVED
FIXED
Taiwan-CA Inc. (TWCA)
AI Summary
Taiwan-CA Inc. (TWCA) identified an issue where 75 EV TLS certificates and 16,406 OV TLS certificates were issued with non-critical basicConstraints, violating BR Section 7.1.2.7. The problem was discovered during an investigation related to a previous bug. Although recently issued certificates were not affected, the mis-issuance required immediate action, including customer notifications and certificate replacements. TWCA has since implemented corrective measures, including the integration of pkilint into their issuance process to prevent future occurrences.
Chronology
- TLS BR 2.0.0 was published.
- TLS BR 2.0.0 became effective.
- Compliance team confirmed the issue and started investigation.
- Preliminary report posted after discovering the issue.
- Internal procedures established and compliance with standards initiated.
- pkilint integrated into the CA system.
- All action items completed; request to close the bug.
Participants
Hao-Chun Li
Chya-Hung Tsai
Ryan Dickson
Rob Stradling
External References
Similar Local Cases
TWCA: "unknown" OCSP response for issued certificates
TWCA: TLS EV certificates with invalid subject attribute order
CFCA: Certificate with wrong crlDistributionPoints
TWCA: Revocation delay for EV TLS certificates with invalid subject attribute order
TWCA: Undisclosed CA
Disig: TLS certificate with basicConstraints not marked as critical
Sectigo: Issuance of ECC leaf certificates with non-DER encoded keyUsage
TWCA: Revocation delay for TLS certificates with non-critical basicConstraints