← Taiwan-CA Inc. (TWCA) cases
Bugzilla #1886110 Delayed Revocation

TWCA delayed revocation incident for OV TLS certificates with non-critical basicConstraints

RESOLVED FIXED Taiwan-CA Inc. (TWCA)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

TWCA reported a delayed revocation incident involving 16,481 OV TLS certificates that were mis-issued with non-critical basicConstraints, which did not conform to BR Section 7.1.2.7.6. TWCA said all affected certificates had to be revoked within 5 days, but 2,551 were not revoked in time. The report described several reasons for the delay, including customer deployment constraints, certificate pinning, wildcard and multi-domain use cases, and technical issues during replacement. Mozilla and other commenters asked follow-up questions about customer use cases, revocation publication timing, and how automation could reduce future delays. TWCA later reported that the remaining certificates were gradually revoked, that ACME ARI had been developed and then launched, and that all action items were completed. The bug was ultimately marked RESOLVED/FIXED, and TWCA requested closure after posting a final report closure summary.

Model: gpt-5.4-mini Generated: 2026-06-13 20:52 UTC Revised: 2026-06-16 18:15 UTC Confidence: 0.97 42 comments
Chronology
  1. TWCA discovered mis-issued OV TLS certificates with non-critical basicConstraints during investigation of a previous bug.
  2. TWCA identified 16,481 affected OV TLS certificates.
  3. The BR revocation deadline passed for the mis-issued certificates.
  4. TWCA said the remaining two affected certificates had been revoked.
  5. TWCA reported that ACME ARI had been successfully launched and all committed action items were completed.
Thread Activity
  1. Taiwan-CA Inc. (TWCA) — TWCA opened the incident report and said 2,551 of 16,481 mis-issued certificates were not revoked within the required 5 days.
  2. Google representative — Google asked whether private PKI would be a better fit for some affected use cases and what role automation could play.
  3. Taiwan-CA Inc. (TWCA) — TWCA replied that it had evaluated private PKI, noted customers with automation had shorter response times, and said such customers were less affected by the incident.
  4. Taiwan-CA Inc. (TWCA) — TWCA posted completed and unfinished items, including customer contact updates, contract updates, staff training, and a two-week extension for the remaining wildcard certificates.
  5. Taiwan-CA Inc. (TWCA) — TWCA clarified the revocation timing and said the two remaining certificates were marked revoked in the database before being published in CRLs later that day.
  6. Taiwan-CA Inc. (TWCA) — TWCA said it had developed ACME ARI using draft-ietf-acme-ari-03, would make it available to all ACME users, and would monitor adoption and test it annually.
  7. Taiwan-CA Inc. (TWCA) — TWCA posted a closure summary, said all action items were completed, and requested that the bug be closed.
  8. Sectigo — Sectigo said it did not yet see a firm commitment to avoid future delayed revocation and suggested TWCA post a clearer policy change.
  9. Taiwan-CA Inc. (TWCA) — TWCA replied by pointing to related responses in Bug 1884568 comment 26.
Participants
Taiwan-CA Inc. (TWCA) Google representative Community commenter Internet Security Research Group Apple representative HARICA Mozilla representative Sectigo
Related Bugzilla IDs Mentioned
Similar Local Cases
#1884568 RESOLVED Delayed Revocation Opened 2024-03-10 · Closed 2025-02-14 · 100% similar
TWCA: Revocation delay for EV TLS certificates with invalid subject attribute order
#1877388 RESOLVED Delayed Revocation Incident Self Reported Incident Opened 2024-01-30 · Closed 2025-03-14 · 91% similar
Telekom Security: Revocation delay for TLS certificates with basicConstraints not marked as critical
#1887888 RESOLVED Delayed Revocation Opened 2024-03-26 · Closed 2025-02-28 · 91% similar
Hongkong Post: Delayed revocation of TLS certificates with basicConstraints not marked as critical
#1887705 RESOLVED Delayed Revocation Opened 2024-03-25 · Closed 2024-09-12 · 89% similar
Entrust: Delayed revocation of clientAuth TLS Certificates without serverAuth EKU
#1891331 RESOLVED Delayed Revocation Opened 2024-04-13 · Closed 2025-03-10 · 89% similar
NETLOCK: Policy Qualifiers other than id-qt-cps is included in TLS certificates - delayed revocation
#1896053 RESOLVED Delayed Revocation Opened 2024-05-10 · Closed 2025-07-16 · 88% similar
Digicert: Delayed Revocation for bug 1894560
#1896553 RESOLVED Delayed Revocation Opened 2024-05-14 · Closed 2025-02-12 · 88% similar
Telia: Delayed revocation of seven (7) certificates related to incident 1896108
#1889062 RESOLVED Delayed Revocation Opened 2024-04-02 · Closed 2025-04-03 · 88% similar
GDCA: Delayed revocation of SSL/TLS certificates with Non-critical Basic Constraints

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action