← Chunghwa Telecom cases
Bugzilla #1951415 Certificate Problem Report

Chunghwa Telecom: Failure to check restrictive CAA record during Migration

RESOLVED FIXED Chunghwa Telecom
AI Summary

Chunghwa Telecom (CHT) faced a significant incident during the migration of TLS certificates from GTLSCA to HiPKI OV TLS CA, where they reused Domain Control Validation (DCV) data without properly checking CAA records. This oversight led to the issuance of 11,860 certificates that were not authorized, as some domains had CAA records that restricted issuance. Upon notification from the Chrome Root Program regarding unusual certificate issuance, CHT promptly initiated a large-scale revocation process, successfully revoking all affected certificates. The incident highlighted procedural weaknesses and the need for improved verification practices.

Model: gpt-4o-mini Generated: 2026-06-13 21:31 UTC Confidence: 0.90
Chronology
  1. Non-compliance start date
  2. Non-compliance identified date
  3. Non-compliance end date
  4. Received notification from Chrome Root Program
  5. Revocation of 11,860 certificates completed
Participants
Tsung-Min Kuo Tim Callan Chrome Root Program
Similar Local Cases
#1956910 RESOLVED Certificate Problem Report Opened 2025-03-27 · Closed 2025-07-16 · 61% similar
Chunghwa Telecom: OV TLS Server certificate issuance by GTLSCA without proper validation
#2025231 RESOLVED Certificate Problem Report Opened 2026-03-23 · Closed 2026-04-24 · 58% similar
Chunghwa Telecom: Test Website certificate not revoked
#2005567 RESOLVED Certificate Problem Report Opened 2025-12-11 · Closed 2026-02-03 · 58% similar
Chunghwa Telecom: CA Certificates Published in PEM format
#2005762 RESOLVED Certificate Problem Report Opened 2025-12-12 · Closed 2026-02-05 · 57% similar
Chunghwa Telecom: Failure to respond to CPR within 24 hours
#1899466 RESOLVED Certificate Problem Report Opened 2024-05-29 · Closed 2024-09-13 · 57% similar
Chunghwa Telecom: Controversial Values within Extension (2.5.29.9, subjectDirectoryAttributes)
#2012274 RESOLVED Certificate Problem Report Opened 2026-01-24 · Closed 2026-03-08 · 56% similar
Chunghwa Telecom: Issuance of certificate using keys previously reported as compromised
#1904038 RESOLVED Certificate Problem Report Opened 2024-06-21 · Closed 2025-04-18 · 56% similar
Chunghwa Telecom: “Test Website - Valid" URL disclosed to CCADB is expired
#1916392 RESOLVED Certificate Problem Report Opened 2024-09-03 · Closed 2025-02-12 · 51% similar
Chunghwa Telecom: TLS Certificates Contains two LocalityName Values in SubjectDN by GTLSCA

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action