← Chunghwa Telecom cases
Bugzilla #1887096 Certificate Misissuance

Chunghwa Telecom: Wrong Extended Key Usage setting by GTLSCA

RESOLVED FIXED Chunghwa Telecom
AI Summary

Chunghwa Telecom's GTLSCA identified a certificate misissuance issue involving approximately 6,450 certificates with incorrect Extended Key Usage (EKU) settings. The problem was reported on March 19, 2024, leading to the immediate revocation of three specific certificates and a broader investigation. Following an impact assessment, GTLSCA decided to automate the renewal of all affected certificates to minimize disruption. The root cause was traced to a misunderstanding of the EKU profile requirements under the new TLS Baseline Requirements, which was corrected on March 11, 2024. All remediation actions were completed by early September 2024.

Model: gpt-4o-mini Generated: 2026-06-13 21:23 UTC Confidence: 0.95
Chronology
  1. Problem report received; initial revocations made.
  2. Incident report posted.
  3. All problematic certificates revoked.
  4. All action items completed; case closed.
Participants
Tsung-Min Kuo Aaron Gable Leo Fang Rob Stradling Amir Aamidi
External References
Similar Local Cases
#1874196 RESOLVED Certificate Misissuance Opened 2024-01-11 · Closed 2024-03-27 · 50% similar
SwissSign: difference in upper and lower case between CN field and SAN
#1532436 RESOLVED Certificate Misissuance Opened 2019-03-04 · Closed 2023-02-22 · 50% similar
Chunghwa Telecom: Test certificate with unregistered domain name
#1710243 RESOLVED Certificate Misissuance Opened 2021-05-08 · Closed 2023-02-22 · 48% similar
Sectigo: Invalid stateOrProvinceName
#2038351 ASSIGNED Certificate Misissuance Opened 2026-05-08 Still Open · 47% similar
Let's Encrypt: Gen Y Cross-Certified Subordinate CAs missing serverAuth EKU
#1891245 RESOLVED Certificate Misissuance Opened 2024-04-12 · Closed 2024-05-13 · 47% similar
Sectigo: EV Certificate issuance with incorrect subject:serialNumber attribute value
#1894054 RESOLVED Certificate Misissuance Opened 2024-04-29 · Closed 2024-07-03 · 47% similar
SwissSign: MPKI step-up process sets wrong JoI Locality
#1676367 RESOLVED Certificate Misissuance Opened 2020-11-10 · Closed 2023-02-22 · 47% similar
NetLock: Issuance of >398-day precertificates after 2020-09-01
#1889570 RESOLVED Certificate Misissuance Opened 2024-04-04 · Closed 2024-08-28 · 47% similar
NETLOCK: Policy Qualifiers other than id-qt-cps is included in TLS certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action