TWCA delayed revocation incident for OV TLS certificates with non-critical basicConstraints
TWCA reported a delayed revocation incident involving 16,481 OV TLS certificates that were mis-issued with non-critical basicConstraints, which did not conform to BR Section 7.1.2.7.6. TWCA said all affected certificates had to be revoked within 5 days, but 2,551 were not revoked in time. The report described several reasons for the delay, including customer deployment constraints, certificate pinning, wildcard and multi-domain use cases, and technical issues during replacement. Mozilla and other commenters asked follow-up questions about customer use cases, revocation publication timing, and how automation could reduce future delays. TWCA later reported that the remaining certificates were gradually revoked, that ACME ARI had been developed and then launched, and that all action items were completed. The bug was ultimately marked RESOLVED/FIXED, and TWCA requested closure after posting a final report closure summary.
- TWCA discovered mis-issued OV TLS certificates with non-critical basicConstraints during investigation of a previous bug.
- TWCA identified 16,481 affected OV TLS certificates.
- The BR revocation deadline passed for the mis-issued certificates.
- TWCA said the remaining two affected certificates had been revoked.
- TWCA reported that ACME ARI had been successfully launched and all committed action items were completed.
- Taiwan-CA Inc. (TWCA) — TWCA opened the incident report and said 2,551 of 16,481 mis-issued certificates were not revoked within the required 5 days.
- Google representative — Google asked whether private PKI would be a better fit for some affected use cases and what role automation could play.
- Taiwan-CA Inc. (TWCA) — TWCA replied that it had evaluated private PKI, noted customers with automation had shorter response times, and said such customers were less affected by the incident.
- Taiwan-CA Inc. (TWCA) — TWCA posted completed and unfinished items, including customer contact updates, contract updates, staff training, and a two-week extension for the remaining wildcard certificates.
- Taiwan-CA Inc. (TWCA) — TWCA clarified the revocation timing and said the two remaining certificates were marked revoked in the database before being published in CRLs later that day.
- Taiwan-CA Inc. (TWCA) — TWCA said it had developed ACME ARI using draft-ietf-acme-ari-03, would make it available to all ACME users, and would monitor adoption and test it annually.
- Taiwan-CA Inc. (TWCA) — TWCA posted a closure summary, said all action items were completed, and requested that the bug be closed.
- Sectigo — Sectigo said it did not yet see a firm commitment to avoid future delayed revocation and suggested TWCA post a clearer policy change.
- Taiwan-CA Inc. (TWCA) — TWCA replied by pointing to related responses in Bug 1884568 comment 26.