← Chunghwa Telecom cases
Bugzilla #2008782 Ca Certificate Compliance

Chunghwa Telecom (GTLSCA): 2025 WebTrust audit finding—mass certificate revocation plan not fully approved/consistent with CAB requirements

RESOLVED FIXED Chunghwa Telecom
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case documents an audit finding for Chunghwa Telecom’s GTLSCA regarding its mass certificate revocation plan. During the audit period, GTLSCA’s mass revocation plan was not approved and its content did not fully comply with CAB requirements, including activation criteria, targets, and timelines. The CA stated the issue was not caused by an active security breach or certificate compromise, but by insufficient procedural readiness and documentation demonstrating the CA’s ability to execute timely and controlled mass revocation. Chunghwa Telecom reported that it had defined a complete execution process and conducted mass revocation drills, but approval and sign-off of supporting evidence could not be fully completed within the audit period due to drill schedule impacts and document governance/timing gaps. Remediation included updating the mass revocation procedures to Version 2 (approved on 2025-11-27) and completing drills on 2025-11-06 and 2025-11-21, along with an audit readiness alignment checklist completed on 2026-01-15 and document governance improvements completed on 2026-01-27. The report closure summary states there were no remaining open deliverables and requests closure; the bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:35 UTC Revised: 2026-06-16 18:09 UTC Confidence: 0.90 7 comments
Chronology
  1. Non-compliance with mass revocation planning requirements began during the audit period.
  2. The audit identified the mass revocation plan non-compliance.
  3. Updated mass revocation procedures (Version 2) were approved and the approval routing process ended.
  4. An audit readiness alignment checklist was completed.
  5. Document governance improvements were completed.
  6. The incident report was scheduled to close and the bug reached RESOLVED status.
Thread Activity
  1. Cht representative — Submitted a preliminary incident report stating GTLSCA’s mass certificate revocation plan was not approved and did not fully comply with CAB requirements (e.g., activation criteria, targets, timelines).
  2. Cht representative — Posted a full incident report with details on the non-compliance window, stating the issue was due to insufficient procedural readiness/documentation rather than a security breach or compromise.
  3. Cht representative — Noted Chunghwa Telecom was monitoring the bug and had no new information.
  4. Cht representative — Provided an action-items update showing completion of procedure/document formalization, audit readiness alignment, and document governance/approval timeliness improvements.
  5. Cht representative — Again stated Chunghwa Telecom was monitoring the bug with no new information.
  6. Cht representative — Submitted the report closure summary describing remediation (Version 2 approval, drills, checklist, governance improvements) and requesting closure with no remaining open deliverables.
  7. CCADB representative — Issued a final call for comments and indicated the incident report would be closed approximately 2026-02-18.
Participants
Cht representative CCADB representative
External References
Similar Local Cases
#2005567 RESOLVED Ca Certificate Compliance Opened 2025-12-11 · Closed 2026-02-03 · 75% similar
Chunghwa Telecom: CA Certificates Published in PEM format
#1887096 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2024-03-22 · Closed 2024-09-06 · 66% similar
Chunghwa Telecom: Wrong Extended Key Usage setting by GTLSCA
#1402158 RESOLVED Ca Certificate Compliance Ca Security Vulnerability Opened 2017-09-21 · Closed 2022-11-14 · 59% similar
Add Certinomis Cross-Signed StartCom certs to OneCRL
#1532436 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2019-03-04 · Closed 2023-02-22 · 59% similar
Chunghwa Telecom: Test certificate with unregistered domain name
#1614444 RESOLVED Ca Certificate Compliance Audit Finding Opened 2020-02-10 · Closed 2024-06-30 · 58% similar
Chunghwa Telecom: ALV failures on intermediate certificates
#1970559 RESOLVED Ca Certificate Compliance Opened 2025-06-05 · Closed 2025-07-08 · 49% similar
ANF AC: Finding #3 ETSI Audit - Improve documental explanation revocation request >24h on CPS
#2019995 RESOLVED Ca Certificate Compliance Opened 2026-02-27 · Closed 2026-04-08 · 48% similar
Sectigo: Package patching gap within Certificate Systems
#1970968 RESOLVED Ca Certificate Compliance Opened 2025-06-06 · Closed 2025-07-08 · 47% similar
Microsoft PKI Services: Incorrect Revocation Reason Code

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action