← Chunghwa Telecom cases
Bugzilla #2008788 Self Reported Incident Audit Finding

Chunghwa Telecom (GTLSCA): WebTrust audit finding—domain validation records missing structured TLS Baseline Requirements version field (GTLSCA Audit Incident Report #2)

RESOLVED FIXED Chunghwa Telecom
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case documents a WebTrust audit finding for Chunghwa Telecom’s GTLSCA (CA owner CCADB unique ID A006506) during the 2025 audit period. The auditors identified that, when creating domain validation records, the recorded information did not include the applicable TLS Baseline Requirements (BR) version number used to validate every domain on the RA system. The CA stated this was an issue with incomplete record-keeping information (record structure and retention/mapping practices), not an error in the domain validation workflow or any certificate misissuance. The CA reported that issuance was not stopped because there were no certificates misissued, and it also stated it had already stopped issuing TLS certificates in early March 2025. As remediation, the CA added a new system-required field to the RA validation record schema to explicitly record the applicable BR version (along with validation method and MPIC Perspectives result) and implemented system-level integrity checks to ensure required validation metadata is present and consistent. The CA reported that there were no remaining open deliverables for the incident and requested closure; the bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:35 UTC Revised: 2026-06-16 18:09 UTC Confidence: 0.86 10 comments
Chronology
  1. Non-compliance period began when TLS BR version 1.5.2 became effective and the RA system’s validation record design did not require BR version as a structured field.
  2. The issuance date of GTLSCA’s first TLS certificate.
  3. The non-compliance was identified during the GTLSCA 2025 audit period (auditing close meeting).
  4. The CA completed an RA program update to fix validation logs so the applicable TLS BR version was specified.
  5. The incident report was closed after Mozilla’s final observations and the CA’s response.
Thread Activity
  1. Cht representative — Submitted a preliminary incident report describing the audit finding that domain validation records lacked the TLS Baseline Requirements version number.
  2. Cht representative — Submitted a full incident report with details including non-compliance dates, scope (record-keeping completeness), and remediation timeline.
  3. Cht representative — Noted Chunghwa Telecom was monitoring the bug for comments/questions and had no new information.
  4. Cht representative — Again stated Chunghwa Telecom was monitoring the bug and had no new information.
  5. Cht representative — Provided a report closure summary stating the issue was limited to how validation records were stored/displayed and describing remediation (structured BR version field and integrity checks).
  6. CCADB representative — Issued a final call for comments and stated the incident would be closed approximately 2026-02-10.
  7. Mozilla representative — Shared Mozilla observations emphasizing the control-design maturity aspect and the need for proactive internal compliance validation.
  8. Cht representative — Agreed with Mozilla’s broader characterization and described additional emphasis on reassessing system designs and strengthening requirement-to-system translation.
Participants
Cht representative CCADB representative Mozilla representative
Similar Local Cases
#2008799 RESOLVED Self Reported Incident Audit Finding Opened 2026-01-06 · Closed 2026-02-19 · 100% similar
Chunghwa Telecom: Findings in 2025 WebTrust Audit - GTLSCA Audit Incident Report #3 - Missing vulnerability scan
#2008803 RESOLVED Self Reported Incident Audit Finding Opened 2026-01-06 · Closed 2026-02-12 · 100% similar
Chunghwa Telecom: Findings in 2025 WebTrust Audit - GTLSCA Audit Incident Report #4 - Missing evaluation for third parties
#2009045 RESOLVED Self Reported Incident Audit Finding Opened 2026-01-07 · Closed 2026-02-19 · 100% similar
Chunghwa Telecom: Delayed disclosure to Bug 2008788 GTLSCA Audit Incident Report #2 - Domain validation records without the TLS BR version
#1904038 RESOLVED Self Reported Incident Revocation Issue Opened 2024-06-21 · Closed 2025-04-18 · 95% similar
Chunghwa Telecom: “Test Website - Valid" URL disclosed to CCADB is expired
#1916392 RESOLVED Self Reported Incident Revocation Issue Opened 2024-09-03 · Closed 2025-02-12 · 95% similar
Chunghwa Telecom: TLS Certificates Contains two LocalityName Values in SubjectDN by GTLSCA
#1947034 RESOLVED Policy Document Issue Self Reported Incident Opened 2025-02-09 · Closed 2025-04-11 · 95% similar
Chunghwa Telecom: outdated and stale policy documents disclosed to the CCADB
#2012274 RESOLVED Self Reported Incident Certificate Misissuance Revocation Issue Opened 2026-01-24 · Closed 2026-03-08 · 95% similar
Chunghwa Telecom: Issuance of certificate using keys previously reported as compromised
#2009046 RESOLVED Self Reported Incident Audit Finding Opened 2026-01-07 · Closed 2026-02-19 · 87% similar
Chunghwa Telecom: Delayed disclosure to Bug 2008799 GTLSCA Audit Incident Report #3 - Missing vulnerability scan

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action