← Chunghwa Telecom cases
Bugzilla #1892419 Delayed Revocation

Chunghwa Telecom: Delayed Revocation Due to GTLSCA EKU Misissuance

RESOLVED FIXED Chunghwa Telecom
AI Summary

On March 19, 2024, Chunghwa Telecom was notified of a misissuance involving incorrect Extended Key Usage (EKU) fields in 6,450 certificates issued by GTLSCA. Although the affected certificates were revoked, the revocation process was delayed due to the need for subscribers, primarily government agencies, to replace their certificates without compromising service availability. The CA has since committed to adhering strictly to Baseline Requirements (BR) for future incidents, ensuring timely revocation without grace periods. The incident was resolved with all affected certificates revoked by May 13, 2024.

Model: gpt-4o-mini Generated: 2026-06-13 21:24 UTC Confidence: 0.90
Chronology
  1. Notification received regarding EKU misissuance.
  2. First batch of certificate revocations commenced.
  3. All affected certificates successfully revoked.
Participants
leox@cht.com.tw amir@aaomidi.com ryandickson@google.com bwilson@mozilla.com tim.callan@sectigo.com
External References
Similar Local Cases
#1903066 RESOLVED Delayed Revocation Opened 2024-06-17 · Closed 2025-02-12 · 81% similar
Chunghwa Telecom: Delayed Revocation with Controversial Extension (2.5.29.9, SubjectDirectoryAttributes)
#1898848 RESOLVED Delayed Revocation Opened 2024-05-25 · Closed 2025-02-21 · 64% similar
Entrust: Delayed revocation of certificates affected by Jurisdiction issue in some EV TLS & Code Signing certificates
#1886532 RESOLVED Delayed Revocation Opened 2024-03-20 · Closed 2025-02-21 · 57% similar
Entrust: Delayed revocation of EV TLS certificates with missing cPSuri
#1959278 RESOLVED Delayed Revocation Opened 2025-04-08 · Closed 2025-06-24 · 51% similar
Chunghwa Telecom: Delayed revocation for bug 1951415
#1889062 RESOLVED Delayed Revocation Opened 2024-04-02 · Closed 2025-04-03 · 49% similar
GDCA: Delayed revocation of SSL/TLS certificates with Non-critical Basic Constraints
#2009045 RESOLVED Delayed Revocation Opened 2026-01-07 · Closed 2026-02-19 · 48% similar
Chunghwa Telecom: Delayed disclosure to Bug 2008788 GTLSCA Audit Incident Report #2 - Domain validation records without the TLS BR version
#1947691 RESOLVED Delayed Revocation Opened 2025-02-12 · Closed 2025-08-19 · 48% similar
NETLOCK: Bug 1891331 replacement - delayed revocation -
#2009048 RESOLVED Delayed Revocation Opened 2026-01-07 · Closed 2026-02-19 · 47% similar
Chunghwa Telecom: Delayed disclosure to Bug 2008803 GTLSCA Audit Incident Report #4 - Missing evaluation for third parties

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action