← Chunghwa Telecom cases
Bugzilla #1956910 Certificate Misissuance

Chunghwa Telecom: OV TLS Server certificate issuance by GTLSCA without proper validation

RESOLVED FIXED Chunghwa Telecom
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Chunghwa Telecom reported a compliance issue involving the issuance of 22 OV TLS certificates by GTLSCA without proper validation of CAA records. The problem was identified during an internal investigation initiated after a third-party report suggested possible mis-issuance. Upon review, it was found that the certificates were issued despite non-compliance with TLS BR requirements. All affected certificates were revoked on March 27, 2025, and the CA has since implemented corrective measures, including retraining personnel and automating CAA checks to prevent future occurrences. The incident has been resolved and the CA is currently undergoing restructuring.

Model: gpt-4o-mini Generated: 2026-06-13 21:32 UTC Revised: 2026-06-16 18:08 UTC Confidence: 0.85 12 comments
Chronology
  1. Revocation of 22 affected certificates completed.
Thread Activity
  1. Cht representative — Preliminary incident report submitted detailing the compliance failure.
  2. Cht representative — Full incident report created outlining the investigation and findings.
  3. Cht representative — Report closure summary provided, detailing remediation actions taken.
Participants
Cht representative CCADB representative Community commenter
Similar Local Cases
#1951415 RESOLVED Certificate Misissuance Delayed Revocation Opened 2025-03-03 · Closed 2025-05-08 · 100% similar
Chunghwa Telecom: Failure to check restrictive CAA record during Migration
#2012274 RESOLVED Self Reported Incident Certificate Misissuance Revocation Issue Opened 2026-01-24 · Closed 2026-03-08 · 100% similar
Chunghwa Telecom: Issuance of certificate using keys previously reported as compromised
#1887096 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2024-03-22 · Closed 2024-09-06 · 98% similar
Chunghwa Telecom: Wrong Extended Key Usage setting by GTLSCA
#1532436 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2019-03-04 · Closed 2023-02-22 · 85% similar
Chunghwa Telecom: Test certificate with unregistered domain name
#2011713 RESOLVED Certificate Misissuance Opened 2026-01-21 · Closed 2026-03-17 · 78% similar
TrustAsia: ACME Authorization Reuse Non-Compliance
#1961406 RESOLVED Certificate Misissuance Opened 2025-04-18 · Closed 2025-07-02 · 78% similar
SSL.com: DCV bypass and issue fake certificates for any MX hostname
#1963663 RESOLVED Incident Certificate Misissuance Opened 2025-04-30 · Closed 2025-06-12 · 75% similar
Certigna: Multiple Reserved Certificate Policy Identifiers in CA certificates
#1981680 RESOLVED Ca Certificate Compliance Self Reported Incident Certificate Misissuance Linting Quality Issue Opened 2025-08-07 · Closed 2025-09-26 · 74% similar
TunTrust: SSL OV mis-issuance against CP/CPS (Email attribute)

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action