← Taiwan-CA Inc. (TWCA) cases
Bugzilla #1885132 Self Reported Incident

TWCA: TLS certificates with non-critical basicConstraints

RESOLVED FIXED Taiwan-CA Inc. (TWCA)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Taiwan-CA Inc. (TWCA) discovered that some of its TLS certificates had the basicConstraints extension not marked as critical, violating CA/Browser Forum Baseline Requirements Section 7.1.2.7. This issue was identified during an investigation related to a previous bug. TWCA confirmed that 75 EV and 16,406 OV TLS certificates were affected and initiated a replacement process for these certificates. The CA has since implemented corrective measures, including the integration of the pkilint tool into its certificate issuance process to prevent future occurrences. The bug has been resolved, and all action items have been completed.

Model: gpt-4o-mini Generated: 2026-06-13 20:52 UTC Revised: 2026-06-16 18:15 UTC Confidence: 0.90 19 comments
Chronology
  1. TWCA discovered non-critical basicConstraints in TLS certificates.
  2. TWCA successfully integrated pkilint into its issuance process.
Thread Activity
  1. Taiwan-CA Inc. (TWCA) — Reported discovery of non-critical basicConstraints in TLS certificates.
  2. Taiwan-CA Inc. (TWCA) — Confirmed the number of affected certificates and initiated replacement operations.
  3. Taiwan-CA Inc. (TWCA) — Requested closure of the bug after completing all action items.
Participants
Taiwan-CA Inc. (TWCA) Google representative Sectigo Mozilla representative
Similar Local Cases
#1883620 RESOLVED Self Reported Incident Opened 2024-03-05 · Closed 2024-07-03 · 93% similar
TWCA: TLS EV certificates with invalid subject attribute order
#1889570 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2024-04-04 · Closed 2024-08-28 · 70% similar
NETLOCK: Policy Qualifiers other than id-qt-cps is included in TLS certificates
#1962809 RESOLVED Self Reported Incident Revocation Issue Opened 2025-04-25 · Closed 2025-07-28 · 66% similar
SSL.com: Expired certificate for a “Valid” Test Website
#1976256 RESOLVED Self Reported Incident Opened 2025-07-08 · Closed 2025-11-20 · 66% similar
IZENPE: IssuingDistributionPoint extension in CRLs not marked as Critical
#1467414 RESOLVED Certificate Misissuance Self Reported Incident Opened 2018-06-07 · Closed 2023-02-22 · 66% similar
GDCA: Misissuance of certificates with small RSA keys
#2007132 RESOLVED Certificate Misissuance Self Reported Incident Opened 2025-12-19 · Closed 2026-02-11 · 66% similar
Disig: Certificates with invalid embedded SCT signature
#1975624 RESOLVED Self Reported Incident Opened 2025-07-04 · Closed 2025-09-24 · 66% similar
SECOM: Cybertrust Japan's CRL lacks the critical flag in the issuingDistributionPoint extension
#1393557 RESOLVED Self Reported Incident Incident Opened 2017-08-24 · Closed 2023-02-22 · 65% similar
GlobalSign: Non-BR-Compliant Certificate Issuance -- RSA key smaller than 2048 bits

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action