Chunghwa Telecom GTLSCA incident report for wrong EKU settings
GTLSCA, on behalf of Chunghwa Telecom, filed this incident report after receiving a certificate mis-issuance notification from the CHT root CA team on 2024-03-19. The report said three listed certificates were revoked promptly, and a broader investigation found about 6,450 certificates with the wrong Extended Key Usage setting. GTLSCA said the issue came from misunderstanding the TLS Baseline Requirements profile and that it had corrected the profile on 2024-03-11, after which newly issued certificates were compliant. The CA later added a delayed revocation list attachment and stated it would revoke and reissue the affected certificates, then opened a separate bug for the delayed revocation matter. Mozilla participants also asked for a fuller timeline and for the affected-certificate list, and the CA later said all action items for this bug had been completed and requested closure.
- TLS Baseline Requirements v2.0.0 became effective.
- GTLSCA updated the certificate profile so extKeyUsage was marked non-critical.
- GTLSCA received the mis-issuance notification and revoked the three listed certificates.
- GTLSCA attached a delayed revocation list covering 6,450 records.
- GTLSCA stopped issuing certificates with the subjectDirectoryAttributes extension and removed it from issuance.
- GTLSCA said all action items for this bug had been completed and asked for closure.
- Cht representative — GTLSCA filed the incident report, described the wrong EKU setting, and said about 6,450 certificates were affected.
- Internet Security Research Group — Requested that the timeline include earlier relevant events such as when the profile settings were introduced and when the first misissued certificate was issued.
- Cht representative — Said the issue traced back to the 2023-09-15 BR effective date, that the problem was found during self-checking on 2024-03-05, and that it was corrected on 2024-03-11.
- Sectigo — Asked for a complete list of affected certificates and said the delayed revocation issue should be handled in a new bug.
- Cht representative — Created the delayed revocation list attachment.
- Cht representative — Posted an expanded timeline and said certificates issued after 2024-03-11 complied with the BRs.
- Cht representative — Said issuance with the subjectDirectoryAttributes extension had been stopped, the extension removed, and issuance resumed without it.
- Cht representative — Said a new post had been opened to explain the issue and revoke all affected issued certificates.
- Cht representative — Said all action items for this bug were complete and requested closure.