Chunghwa Telecom (GTLSCA): 2025 WebTrust audit finding—mass certificate revocation plan not fully approved/consistent with CAB requirements
This case documents an audit finding for Chunghwa Telecom’s GTLSCA regarding its mass certificate revocation plan. During the audit period, GTLSCA’s mass revocation plan was not approved and its content did not fully comply with CAB requirements, including activation criteria, targets, and timelines. The CA stated the issue was not caused by an active security breach or certificate compromise, but by insufficient procedural readiness and documentation demonstrating the CA’s ability to execute timely and controlled mass revocation. Chunghwa Telecom reported that it had defined a complete execution process and conducted mass revocation drills, but approval and sign-off of supporting evidence could not be fully completed within the audit period due to drill schedule impacts and document governance/timing gaps. Remediation included updating the mass revocation procedures to Version 2 (approved on 2025-11-27) and completing drills on 2025-11-06 and 2025-11-21, along with an audit readiness alignment checklist completed on 2026-01-15 and document governance improvements completed on 2026-01-27. The report closure summary states there were no remaining open deliverables and requests closure; the bug is marked RESOLVED with resolution FIXED.
- Non-compliance with mass revocation planning requirements began during the audit period.
- The audit identified the mass revocation plan non-compliance.
- Updated mass revocation procedures (Version 2) were approved and the approval routing process ended.
- An audit readiness alignment checklist was completed.
- Document governance improvements were completed.
- The incident report was scheduled to close and the bug reached RESOLVED status.
- Cht representative — Submitted a preliminary incident report stating GTLSCA’s mass certificate revocation plan was not approved and did not fully comply with CAB requirements (e.g., activation criteria, targets, timelines).
- Cht representative — Posted a full incident report with details on the non-compliance window, stating the issue was due to insufficient procedural readiness/documentation rather than a security breach or compromise.
- Cht representative — Noted Chunghwa Telecom was monitoring the bug and had no new information.
- Cht representative — Provided an action-items update showing completion of procedure/document formalization, audit readiness alignment, and document governance/approval timeliness improvements.
- Cht representative — Again stated Chunghwa Telecom was monitoring the bug with no new information.
- Cht representative — Submitted the report closure summary describing remediation (Version 2 approval, drills, checklist, governance improvements) and requesting closure with no remaining open deliverables.
- CCADB representative — Issued a final call for comments and indicated the incident report would be closed approximately 2026-02-18.