← Taiwan-CA Inc. (TWCA) cases
Bugzilla #1886110 Certificate Problem Report

TWCA: Revocation delay for TLS certificates with non-critical basicConstraints

RESOLVED FIXED Taiwan-CA Inc. (TWCA)
AI Summary

TWCA mis-issued 16,481 OV TLS certificates with non-conforming basicConstraints, violating BR Section 7.1.2.7.6. Although all affected certificates were required to be revoked within 5 days, 2,551 certificates were not revoked in time due to various customer-related challenges. The CA has since completed the revocation of all remaining certificates and has committed to stricter policies to prevent future delays in revocation. The incident highlighted the need for better communication with customers regarding the importance of timely revocation and the risks associated with certificate binding.

Model: gpt-4o-mini Generated: 2026-06-13 20:52 UTC Confidence: 0.95
Chronology
  1. Preliminary incident report posted.
  2. All affected certificates have been revoked.
  3. Report closure summary provided.
Participants
chtsai@twca.com.tw bwilson@mozilla.com tim.callan@sectigo.com rdaurne77@gmail.com mike.shaver@gmail.com aaron@letsencrypt.org clintw@apple.com dzacharo@harica.gr ryandickson@google.com
Related Bugzilla IDs Mentioned
Similar Local Cases
#1965612 RESOLVED Certificate Problem Report Opened 2025-05-10 · Closed 2026-05-04 · 64% similar
Microsoft PKI Services: Failure to Revoke in 5 Days for 1962829
#1905419 RESOLVED Certificate Problem Report Opened 2024-06-28 · Closed 2024-10-31 · 63% similar
GoDaddy: Intermittent unauthorized OCSP response when certificate is freshly issued
#1897346 RESOLVED Certificate Problem Report Opened 2024-05-17 · Closed 2024-07-24 · 63% similar
SECOM: Difference in upper and lower case between CN field and SAN
#1883620 RESOLVED Certificate Problem Report Opened 2024-03-05 · Closed 2024-07-03 · 61% similar
TWCA: TLS EV certificates with invalid subject attribute order
#1884568 RESOLVED Certificate Problem Report Opened 2024-03-10 · Closed 2025-02-14 · 61% similar
TWCA: Revocation delay for EV TLS certificates with invalid subject attribute order
#2004521 RESOLVED Certificate Problem Report Opened 2025-12-06 · Closed 2026-01-13 · 58% similar
TWCA: CA Certificate not published in DER Encoded Format
#2034251 RESOLVED Certificate Problem Report Opened 2026-04-22 · Closed 2026-05-13 · 57% similar
Microsoft PKI Services: Failure to Update Full Incident Report within 14 days of discovering new root cause
#1885754 RESOLVED Certificate Problem Report Opened 2024-03-16 · Closed 2024-09-13 · 56% similar
Entrust: CPR was not responded to in 24 hours

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action