TWCA: Missing or Inconsistent Disclosure of S/MIME BR Audits
This case involves Taiwan-CA Inc. (TWCA) addressing a compliance issue regarding the disclosure of S/MIME BR audits. The issue was identified when it was noted that the TWCA CYBER Root CA was missing from the S/MIME audit report. Following discussions, TWCA confirmed that the self-signed root certificate would be included in the audit report after obtaining approval from their auditor. The audit report was subsequently updated and uploaded to the Common CA Database (CCADB) on March 14, 2025. TWCA has committed to stricter scrutiny for future audits and ensuring that all new cross certificates will include the EKU field as per current Baseline Requirements.
- Non-compliance identified regarding missing S/MIME BR audit report for TWCA CYBER Root CA.
- Approval obtained to include the TWCA CYBER Root CA in the S/MIME audit report.
- Updated audit report uploaded to CCADB.
- Taiwan-CA Inc. (TWCA) — Preliminary Incident Report published regarding missing S/MIME BR audit.
- Mozilla representative — Clarified that the self-signed root certificate should not be included in the S/MIME audit report.
- Taiwan-CA Inc. (TWCA) — Confirmed inclusion of the self-signed root certificate in the S/MIME audit report.
- Taiwan-CA Inc. (TWCA) — Report Closure Summary submitted, confirming completion of action items.