TWCA: CA Certificate not published in DER Encoded Format
The case concerns TWCA’s CYBER Root CA certificate download artifact being published in the wrong encoding format. The TWCA CYBER Root CA’s SubCAs contained a root CA download link in the AIA field, but the referenced CA certificate file was PEM encoded rather than DER encoded as required by RFC 5280 Section 4.2.2.1. The issue was disclosed on Bugzilla after TWCA received a notification from a third party that the CA certificate encoding format was incorrect. TWCA reported that the non-compliance was identified on 2025-12-06 and that the incorrectly encoded file was replaced with a correctly DER-encoded version, with the replacement completed and verified. TWCA also stated that it manually checked all CA certificate download locations and all CRL download locations for correct encoding and found no encoding errors. TWCA further reported updates to its automated verification tooling (AutoWorker) and revisions to certificate operation SOPs, and requested closure after completing all disclosed action items.
- Non-compliance began: the externally downloadable CA certificate file was published in PEM rather than DER format.
- TWCA identified the encoding issue after a third-party notification and replaced the externally downloadable CA certificate file with a DER-encoded version.
- TWCA completed manual checks of all CA certificate and CRL download locations for correct encoding.
- TWCA reported remediation completion and requested incident report closure.
- Taiwan-CA Inc. (TWCA) — TWCA disclosed a preliminary incident report stating the root CA download link in AIA pointed to a PEM-encoded CA certificate file instead of DER as required by RFC 5280, and noted the issue was third-party reported.
- Taiwan-CA Inc. (TWCA) — TWCA provided a full incident report with timeline details and stated the file replacement was completed and verified.
- Taiwan-CA Inc. (TWCA) — TWCA posted an additional full incident report update including further timeline items and manual verification results.
- Taiwan-CA Inc. (TWCA) — TWCA stated action items were in progress and requested the next update date be set for 2026/1/15.
- Apple representative — Apple asked whether TWCA monitors community incident reports and how the issue was identified via third-party reporting.
- Taiwan-CA Inc. (TWCA) — TWCA responded that it has documented mechanisms for monitoring community activities and explained that internal validation scope was not comprehensive enough to detect the specific error.
- Taiwan-CA Inc. (TWCA) — TWCA reported that it incorporated work items into its Certificate Operational SOP, marked final action items as complete, and listed the action items and statuses.
- Taiwan-CA Inc. (TWCA) — TWCA provided a report closure summary describing the incident scope, remediation steps (including file replacement and manual reviews), and requested closure.
- CCADB representative — CCADB issued a final call for comments and stated the incident report would be closed approximately 2026-01-13.