← Chunghwa Telecom cases
Bugzilla #1903066 Delayed Revocation

Chunghwa Telecom: Delayed Revocation with Controversial Extension (2.5.29.9, SubjectDirectoryAttributes)

RESOLVED FIXED Chunghwa Telecom
AI Summary

Chunghwa Telecom faced challenges in revoking 12,911 certificates due to the use of a controversial extension in compliance with Baseline Requirements (BR). The revocation process was complicated by the short time frame between this incident and a previous one, impacting government agency operations. Despite efforts to communicate and coordinate with users, the full revocation could not be completed within the mandated timeframe. The CA has committed to adhering strictly to BR requirements in the future, ensuring timely revocations without grace periods.

Model: gpt-4o-mini Generated: 2026-06-13 21:26 UTC Confidence: 0.90
Chronology
  1. Stopped issuing certificates with the controversial extension.
  2. Revoked the first batch of certificates.
  3. Completed revocation of all affected certificates.
  4. Chunghwa Telecom committed to strict adherence to BR requirements.
Participants
leox@cht.com.tw mike.shaver@gmail.com tim.callan@sectigo.com bwilson@mozilla.com ryandickson@google.com walter.j.marks@proton.me
External References
Similar Local Cases
#1892419 RESOLVED Delayed Revocation Opened 2024-04-19 · Closed 2025-02-12 · 81% similar
Chunghwa Telecom: Delayed Revocation Due to GTLSCA EKU Misissuance
#1886532 RESOLVED Delayed Revocation Opened 2024-03-20 · Closed 2025-02-21 · 58% similar
Entrust: Delayed revocation of EV TLS certificates with missing cPSuri
#1889062 RESOLVED Delayed Revocation Opened 2024-04-02 · Closed 2025-04-03 · 56% similar
GDCA: Delayed revocation of SSL/TLS certificates with Non-critical Basic Constraints
#1898848 RESOLVED Delayed Revocation Opened 2024-05-25 · Closed 2025-02-21 · 55% similar
Entrust: Delayed revocation of certificates affected by Jurisdiction issue in some EV TLS & Code Signing certificates
#1959278 RESOLVED Delayed Revocation Opened 2025-04-08 · Closed 2025-06-24 · 51% similar
Chunghwa Telecom: Delayed revocation for bug 1951415
#2009045 RESOLVED Delayed Revocation Opened 2026-01-07 · Closed 2026-02-19 · 49% similar
Chunghwa Telecom: Delayed disclosure to Bug 2008788 GTLSCA Audit Incident Report #2 - Domain validation records without the TLS BR version
#1651487 RESOLVED Delayed Revocation Opened 2020-07-08 · Closed 2023-02-22 · 49% similar
Telekom Security: Delayed Revocations of Sub-CA certificates
#1947691 RESOLVED Delayed Revocation Opened 2025-02-12 · Closed 2025-08-19 · 48% similar
NETLOCK: Bug 1891331 replacement - delayed revocation -

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action