← Taiwan-CA Inc. (TWCA) cases
Bugzilla #2004521 Certificate Misissuance

TWCA: CA Certificate not published in DER Encoded Format

RESOLVED FIXED Taiwan-CA Inc. (TWCA)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The case concerns TWCA’s CYBER Root CA certificate download artifact being published in the wrong encoding format. The TWCA CYBER Root CA’s SubCAs contained a root CA download link in the AIA field, but the referenced CA certificate file was PEM encoded rather than DER encoded as required by RFC 5280 Section 4.2.2.1. The issue was disclosed on Bugzilla after TWCA received a notification from a third party that the CA certificate encoding format was incorrect. TWCA reported that the non-compliance was identified on 2025-12-06 and that the incorrectly encoded file was replaced with a correctly DER-encoded version, with the replacement completed and verified. TWCA also stated that it manually checked all CA certificate download locations and all CRL download locations for correct encoding and found no encoding errors. TWCA further reported updates to its automated verification tooling (AutoWorker) and revisions to certificate operation SOPs, and requested closure after completing all disclosed action items.

Model: gpt-5.4-nano Generated: 2026-06-13 20:53 UTC Revised: 2026-06-16 18:15 UTC Confidence: 0.62 10 comments
Chronology
  1. Non-compliance began: the externally downloadable CA certificate file was published in PEM rather than DER format.
  2. TWCA identified the encoding issue after a third-party notification and replaced the externally downloadable CA certificate file with a DER-encoded version.
  3. TWCA completed manual checks of all CA certificate and CRL download locations for correct encoding.
  4. TWCA reported remediation completion and requested incident report closure.
Thread Activity
  1. Taiwan-CA Inc. (TWCA) — TWCA disclosed a preliminary incident report stating the root CA download link in AIA pointed to a PEM-encoded CA certificate file instead of DER as required by RFC 5280, and noted the issue was third-party reported.
  2. Taiwan-CA Inc. (TWCA) — TWCA provided a full incident report with timeline details and stated the file replacement was completed and verified.
  3. Taiwan-CA Inc. (TWCA) — TWCA posted an additional full incident report update including further timeline items and manual verification results.
  4. Taiwan-CA Inc. (TWCA) — TWCA stated action items were in progress and requested the next update date be set for 2026/1/15.
  5. Apple representative — Apple asked whether TWCA monitors community incident reports and how the issue was identified via third-party reporting.
  6. Taiwan-CA Inc. (TWCA) — TWCA responded that it has documented mechanisms for monitoring community activities and explained that internal validation scope was not comprehensive enough to detect the specific error.
  7. Taiwan-CA Inc. (TWCA) — TWCA reported that it incorporated work items into its Certificate Operational SOP, marked final action items as complete, and listed the action items and statuses.
  8. Taiwan-CA Inc. (TWCA) — TWCA provided a report closure summary describing the incident scope, remediation steps (including file replacement and manual reviews), and requested closure.
  9. CCADB representative — CCADB issued a final call for comments and stated the incident report would be closed approximately 2026-01-13.
Participants
Taiwan-CA Inc. (TWCA) Apple representative CCADB representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1988405 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2025-09-13 · Closed 2025-10-22 · 68% similar
TunTrust: Issue with Valid test Certificate
#1970259 RESOLVED Certificate Misissuance Incident Self Reported Incident Opened 2025-06-03 · Closed 2025-08-26 · 67% similar
GoDaddy: Precertificates incorrectly logged to DigiCert SCT Logs
#1943379 RESOLVED Certificate Misissuance Opened 2025-01-23 · Closed 2025-05-08 · 67% similar
Actalis: CRL with duplicate serial number in revokedCertificates
#2032485 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2026-04-16 · Closed 2026-05-04 · 66% similar
DigiCert: Misissuance detected by PKIMetal
#2015186 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2026-02-06 · Closed 2026-03-23 · 64% similar
DigiCert: Subject Serial Numbers for Non-Commercial Entities
#2041774 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Repository Issue Opened 2026-05-22 Still Open · 61% similar
OATI: AIA CA Issuer field pointing to PEM encoded cert
#1914466 RESOLVED Certificate Misissuance Opened 2024-08-22 · Closed 2024-10-02 · 61% similar
eMudhra emSign PKI Services: CA Certificates not published in DER Encoded Format
#1645708 RESOLVED Certificate Misissuance Opened 2020-06-14 · Closed 2023-02-22 · 60% similar
QuoVadis: EV serialNumber with "none"

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action