← Taiwan-CA Inc. (TWCA) cases
Bugzilla #2004521
Certificate Problem Report
TWCA: CA Certificate not published in DER Encoded Format
RESOLVED
FIXED
Taiwan-CA Inc. (TWCA)
AI Summary
The TWCA CYBER Root CA's SubCA certificate was found to be PEM encoded instead of the required DER encoding as per RFC 5280. This issue was identified through a third-party report on December 6, 2025, and was resolved the same day by replacing the incorrectly encoded certificate with a compliant version. The incident did not affect the validity of any issued certificates, as the error was limited to the external download link. TWCA has since updated its procedures to prevent similar issues in the future.
Chronology
- Non-compliance start date
- Non-compliance identified and resolved
Participants
chtsai@twca.com.tw
dhollenback@apple.com
orca@twca.com.tw
External References
Similar Local Cases
TWCA: TLS EV certificates with invalid subject attribute order
TWCA: Revocation delay for TLS certificates with non-critical basicConstraints
TWCA: "unknown" OCSP response for issued certificates
TWCA: TLS certificates with non-critical basicConstraints
Telekom Security: Root-CA certificates published in PEM encoded format
TWCA: Undisclosed CA
TWCA: Revocation delay for EV TLS certificates with invalid subject attribute order
NAVER Cloud Trust Services: CA Certificate not published in DER Encoded Format