Chunghwa Telecom incident report: CAA checking was skipped during certificate migration, leading to revocation of 11,860 certificates
Chunghwa Telecom (CHT) reported an incident involving its migration of TLS certificates from GTLSCA to HiPKI OV TLS CA. CHT said it reused prior domain validation data during the migration and did not thoroughly check CAA records, which led to issuance of certificates for domains whose CAA records did not authorize HiPKI OV TLS CA. After being notified by the Chrome Root Program on 2025-03-01, CHT investigated the issue and revoked the affected certificates in bulk. The report was later corrected and expanded, and CHT stated that 11,860 certificates were revoked in total, with no remaining valid affected certificates. In later comments, CHT acknowledged that the revocation was delayed under TLS BR 4.9.1.1 Item 5 and said it would use the case as a lesson learned, retrain staff, and avoid batch migration in the future. The bug was closed as resolved/fixed.
- CHT defined and developed a batch process to reissue certificates during migration from GTLSCA to HiPKI.
- The batch process was first used in production to issue a certificate.
- Chrome Root Program notified CHT about unusual issuance and possible CAA-checking issues; CHT began incident response and revocation.
- CHT identified four additional affected certificates and revoked them, bringing the total revoked to 11,860.
- CHT posted a closure summary stating the remediation actions were completed and requesting closure.
- Cht representative — CHT opened the incident report, described the migration, said CAA checking had not been thoroughly performed, and said it revoked all affected certificates.
- Google representative — Chrome Root Program asked CHT to update the report to the current CCADB incident-reporting format and requested clarifications about DCV, CAA checking, and the MODA/CHT relationship.
- Cht representative — CHT said the report had been corrected and explained its view of DCV, CAA checking, and the GTLSCA/MODA relationship.
- Google representative — Chrome Root Program said the report still lacked detail and asked follow-up questions about revocation timing, delegated third-party status, and the screenshots.
- Cht representative — CHT said it would reply that day and later stated it did not deny inappropriate reuse of GTLSCA/MODA DCV data.
- Cht representative — CHT confirmed the screenshot showed a CAA check log before issuance and said the GTLSCA RAO did not stop issuance, resulting in misissuance.
- Cht representative — CHT said it discovered GTLSCA did not block issuance when CAA records were non-compliant and said it would report the misissued incident on Bugzilla.
- Google representative — Chrome Root Program said CAA checking and DCV are separate processes and that a 24-hour revocation window was more appropriate.
- Cht representative — CHT said it agreed there had been a revocation delay and that it would watch for similar cases and address them promptly.
- Cht representative — CHT posted a closure summary saying the revocation and remediation actions were completed and that batch processing would not be used again.