← Chunghwa Telecom cases
Bugzilla #1904038 Self Reported Incident Revocation Issue

Chunghwa Telecom: “Test Website - Valid" URL disclosed to CCADB is expired

RESOLVED FIXED Chunghwa Telecom
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Chunghwa Telecom disclosed an incident regarding an expired certificate for the URL good.epkiov.hinet.net, which had been expired for 278 days. The issue was identified during communication with a browser contact. The CA took corrective actions, including replacing the expired certificate and implementing an automatic certificate renewal mechanism to prevent future occurrences. The incident report was deemed initially lacking in detail, prompting a restructuring of the timeline and additional action items. The CA has since completed all action items and requested closure of the incident.

Model: gpt-4o-mini Generated: 2026-06-13 21:27 UTC Revised: 2026-06-16 14:35 UTC Confidence: 0.85 17 comments
Chronology
  1. CA received notification of expired certificate.
  2. CA completed certificate replacement.
  3. Incident closure requested after implementing corrective measures.
Thread Activity
  1. Cht representative — Incident report submitted detailing the expired certificate.
  2. Binaryparadox representative — Commented on the lack of detail in the incident report.
  3. Cht representative — Restructured the timeline with additional details.
  4. Cht representative — Reported completion of all action items and requested closure.
  5. Mozilla representative — Indicated intent to close the incident report.
Participants
Cht representative Binaryparadox representative Mozilla representative
External References
Similar Local Cases
#1916392 RESOLVED Self Reported Incident Revocation Issue Opened 2024-09-03 · Closed 2025-02-12 · 100% similar
Chunghwa Telecom: TLS Certificates Contains two LocalityName Values in SubjectDN by GTLSCA
#2012274 RESOLVED Self Reported Incident Certificate Misissuance Revocation Issue Opened 2026-01-24 · Closed 2026-03-08 · 98% similar
Chunghwa Telecom: Issuance of certificate using keys previously reported as compromised
#2008803 RESOLVED Self Reported Incident Audit Finding Opened 2026-01-06 · Closed 2026-02-12 · 96% similar
Chunghwa Telecom: Findings in 2025 WebTrust Audit - GTLSCA Audit Incident Report #4 - Missing evaluation for third parties
#1947034 RESOLVED Policy Document Issue Self Reported Incident Opened 2025-02-09 · Closed 2025-04-11 · 95% similar
Chunghwa Telecom: outdated and stale policy documents disclosed to the CCADB
#2008788 RESOLVED Self Reported Incident Audit Finding Opened 2026-01-06 · Closed 2026-02-11 · 95% similar
Chunghwa Telecom: Findings in 2025 WebTrust Audit - GTLSCA Audit Incident Report #2 - Domain validation records without the TLS BR version
#2008260 RESOLVED Self Reported Incident Opened 2025-12-31 · Closed 2026-02-19 · 89% similar
Chunghwa Telecom: Delayed audit disclosure for GTLSCA
#2009045 RESOLVED Self Reported Incident Audit Finding Opened 2026-01-07 · Closed 2026-02-19 · 88% similar
Chunghwa Telecom: Delayed disclosure to Bug 2008788 GTLSCA Audit Incident Report #2 - Domain validation records without the TLS BR version
#2008799 RESOLVED Self Reported Incident Audit Finding Opened 2026-01-06 · Closed 2026-02-19 · 87% similar
Chunghwa Telecom: Findings in 2025 WebTrust Audit - GTLSCA Audit Incident Report #3 - Missing vulnerability scan

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action