← Chunghwa Telecom cases
Bugzilla #1956910 Certificate Problem Report

Chunghwa Telecom: OV TLS Server certificate issuance by GTLSCA without proper validation

RESOLVED FIXED Chunghwa Telecom
AI Summary

Chunghwa Telecom reported an incident involving the issuance of 22 OV TLS certificates by GTLSCA that did not comply with CAA record checks as mandated by TLS BR. The issue was identified during an investigation triggered by a report from the Chrome Root Program. Upon review, it was found that the certificates were issued despite non-compliance with the required CAA checks, leading to their revocation on March 27, 2025. The incident highlighted deficiencies in GTLSCA's understanding of CAA records and the lack of automated checks, prompting immediate corrective actions and retraining of personnel.

Model: gpt-4o-mini Generated: 2026-06-13 21:32 UTC Confidence: 0.95
Chronology
  1. First non-compliant certificate issued
  2. Non-compliance identified
  3. All affected certificates revoked
  4. Full incident report created
  5. Final call for comments on incident report
Participants
Tsung-Min Kuo leox@cht.com.tw tjtncks@gmail.com incident-reporting@ccadb.org
Similar Local Cases
#2025231 RESOLVED Certificate Problem Report Opened 2026-03-23 · Closed 2026-04-24 · 62% similar
Chunghwa Telecom: Test Website certificate not revoked
#1951415 RESOLVED Certificate Problem Report Opened 2025-03-03 · Closed 2025-05-08 · 61% similar
Chunghwa Telecom: Failure to check restrictive CAA record during Migration
#2012274 RESOLVED Certificate Problem Report Opened 2026-01-24 · Closed 2026-03-08 · 60% similar
Chunghwa Telecom: Issuance of certificate using keys previously reported as compromised
#2005567 RESOLVED Certificate Problem Report Opened 2025-12-11 · Closed 2026-02-03 · 60% similar
Chunghwa Telecom: CA Certificates Published in PEM format
#2005762 RESOLVED Certificate Problem Report Opened 2025-12-12 · Closed 2026-02-05 · 57% similar
Chunghwa Telecom: Failure to respond to CPR within 24 hours
#1904038 RESOLVED Certificate Problem Report Opened 2024-06-21 · Closed 2025-04-18 · 57% similar
Chunghwa Telecom: “Test Website - Valid" URL disclosed to CCADB is expired
#1916392 RESOLVED Certificate Problem Report Opened 2024-09-03 · Closed 2025-02-12 · 52% similar
Chunghwa Telecom: TLS Certificates Contains two LocalityName Values in SubjectDN by GTLSCA
#1899466 RESOLVED Certificate Problem Report Opened 2024-05-29 · Closed 2024-09-13 · 51% similar
Chunghwa Telecom: Controversial Values within Extension (2.5.29.9, subjectDirectoryAttributes)

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action