← Chunghwa Telecom cases
Bugzilla #1899466
Certificate Problem Report
Chunghwa Telecom: Controversial Values within Extension (2.5.29.9, subjectDirectoryAttributes)
RESOLVED
FIXED
Chunghwa Telecom
AI Summary
Chunghwa Telecom identified a controversial value in the 2.5.29.9 (subjectDirectoryAttributes) extension of their certificates, leading to the decision to remove it to comply with BR regulations. A total of 12,911 certificates were affected, prompting a revocation and reissuance process. The CA faced challenges in meeting the 5-day revocation requirement due to the nature of their subscribers, primarily government agencies, which complicated timely certificate replacement. Despite these issues, all action items have been completed, and the case is now resolved.
Chronology
- Investigated and reviewed the cause of the issue.
- Started reissuing certificates after removing the controversial extension.
- All action items completed; case requested to be closed.
Participants
Leo Fang
Tim Callan
Amir Aamidi
R. Daurne
External References
Similar Local Cases
Chunghwa Telecom: TLS Certificates Contains two LocalityName Values in SubjectDN by GTLSCA
Chunghwa Telecom: Failure to check restrictive CAA record during Migration
ACCV: Certificates issued with Policy qualifiers other than id-qt-cps
Chunghwa Telecom: Test Website certificate not revoked
Chunghwa Telecom: OV TLS Server certificate issuance by GTLSCA without proper validation
Chunghwa Telecom: Issuance of certificate using keys previously reported as compromised
Chunghwa Telecom: Failure to respond to CPR within 24 hours
Chunghwa Telecom: “Test Website - Valid" URL disclosed to CCADB is expired