← Chunghwa Telecom cases
Bugzilla #1951415 Certificate Misissuance Delayed Revocation

Chunghwa Telecom incident report: CAA checking was skipped during certificate migration, leading to revocation of 11,860 certificates

RESOLVED FIXED Chunghwa Telecom
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Chunghwa Telecom (CHT) reported an incident involving its migration of TLS certificates from GTLSCA to HiPKI OV TLS CA. CHT said it reused prior domain validation data during the migration and did not thoroughly check CAA records, which led to issuance of certificates for domains whose CAA records did not authorize HiPKI OV TLS CA. After being notified by the Chrome Root Program on 2025-03-01, CHT investigated the issue and revoked the affected certificates in bulk. The report was later corrected and expanded, and CHT stated that 11,860 certificates were revoked in total, with no remaining valid affected certificates. In later comments, CHT acknowledged that the revocation was delayed under TLS BR 4.9.1.1 Item 5 and said it would use the case as a lesson learned, retrain staff, and avoid batch migration in the future. The bug was closed as resolved/fixed.

Model: gpt-5.4-mini Generated: 2026-06-13 21:31 UTC Revised: 2026-06-16 18:07 UTC Confidence: 0.96 31 comments
Chronology
  1. CHT defined and developed a batch process to reissue certificates during migration from GTLSCA to HiPKI.
  2. The batch process was first used in production to issue a certificate.
  3. Chrome Root Program notified CHT about unusual issuance and possible CAA-checking issues; CHT began incident response and revocation.
  4. CHT identified four additional affected certificates and revoked them, bringing the total revoked to 11,860.
  5. CHT posted a closure summary stating the remediation actions were completed and requesting closure.
Thread Activity
  1. Cht representative — CHT opened the incident report, described the migration, said CAA checking had not been thoroughly performed, and said it revoked all affected certificates.
  2. Google representative — Chrome Root Program asked CHT to update the report to the current CCADB incident-reporting format and requested clarifications about DCV, CAA checking, and the MODA/CHT relationship.
  3. Cht representative — CHT said the report had been corrected and explained its view of DCV, CAA checking, and the GTLSCA/MODA relationship.
  4. Google representative — Chrome Root Program said the report still lacked detail and asked follow-up questions about revocation timing, delegated third-party status, and the screenshots.
  5. Cht representative — CHT said it would reply that day and later stated it did not deny inappropriate reuse of GTLSCA/MODA DCV data.
  6. Cht representative — CHT confirmed the screenshot showed a CAA check log before issuance and said the GTLSCA RAO did not stop issuance, resulting in misissuance.
  7. Cht representative — CHT said it discovered GTLSCA did not block issuance when CAA records were non-compliant and said it would report the misissued incident on Bugzilla.
  8. Google representative — Chrome Root Program said CAA checking and DCV are separate processes and that a 24-hour revocation window was more appropriate.
  9. Cht representative — CHT said it agreed there had been a revocation delay and that it would watch for similar cases and address them promptly.
  10. Cht representative — CHT posted a closure summary saying the revocation and remediation actions were completed and that batch processing would not be used again.
Participants
Cht representative Sectigo Google representative Community commenter Mozilla representative Internet Security Research Group HARICA CCADB representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1887096 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2024-03-22 · Closed 2024-09-06 · 100% similar
Chunghwa Telecom: Wrong Extended Key Usage setting by GTLSCA
#1956910 RESOLVED Certificate Misissuance Opened 2025-03-27 · Closed 2025-07-16 · 100% similar
Chunghwa Telecom: OV TLS Server certificate issuance by GTLSCA without proper validation
#2012274 RESOLVED Self Reported Incident Certificate Misissuance Revocation Issue Opened 2026-01-24 · Closed 2026-03-08 · 98% similar
Chunghwa Telecom: Issuance of certificate using keys previously reported as compromised
#1532436 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2019-03-04 · Closed 2023-02-22 · 90% similar
Chunghwa Telecom: Test certificate with unregistered domain name
#1943596 RESOLVED Certificate Misissuance Delayed Revocation Opened 2025-01-24 · Closed 2025-05-01 · 86% similar
HARICA: S/MIME certificate issuance with incorrect commonName
#1903066 RESOLVED Delayed Revocation Opened 2024-06-17 · Closed 2025-02-12 · 86% similar
Chunghwa Telecom: Delayed Revocation with Controversial Extension (2.5.29.9, SubjectDirectoryAttributes)
#1963663 RESOLVED Incident Certificate Misissuance Opened 2025-04-30 · Closed 2025-06-12 · 86% similar
Certigna: Multiple Reserved Certificate Policy Identifiers in CA certificates
#1910322 RESOLVED Certificate Misissuance Revocation Issue Opened 2024-07-29 · Closed 2025-06-18 · 85% similar
DigiCert: Random value in CNAME without underscore prefix

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action