← Chunghwa Telecom cases
Bugzilla #2008803 Self Reported Incident Audit Finding

Chunghwa Telecom (GTLSCA): 2025 WebTrust audit finding—missing objective evidence for third-party evaluation (Criterion 3.1.11)

RESOLVED FIXED Chunghwa Telecom
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns Chunghwa Telecom’s GTLSCA WebTrust audit finding that, during the 2025 audit period, no objective evidence was found regarding GTLSCA’s audit and evaluation of third parties with access to CA facilities and systems. The finding was tied to WebTrust for CA V2.2.2 Criterion 3.1.11, which requires that arrangements involving third-party access be based on a formal contract containing necessary security requirements, and that the CA maintain adequate evaluation evidence. Chunghwa Telecom stated that the issue originated from an auditor-identified problem during GTLSCA’s 2025 audit period, with the non-compliance period described as starting 2024-10-01 and ending 2025-12-23. Chunghwa Telecom reported that no certificates were misissued and noted that GTLSCA had already ceased TLS certificate issuance in early March 2025, so issuance was not suspended as part of this incident. Remediation actions included completing a retrospective third-party evaluation with contract validation and evidence collection (completed 2025-12-23), integrating vendor evaluation and risk assessment into an internal quarterly audit plan and checklist (completed 2025-12-23), and revising internal control assessment processes with follow-up procedures for non-compliant items (completed 2026-01-08). Mozilla’s incident-reporting comment indicated the remediation appeared responsive and that the deficiency reflected a governance integration gap, and Chunghwa Telecom agreed and committed to strengthening continuous compliance assurance and cross-functional coupling. The bug is marked RESOLVED with resolution FIXED, and the report closure summary requested closure after completion of the disclosed action items.

Model: gpt-5.4-nano Generated: 2026-06-13 21:36 UTC Revised: 2026-06-16 18:10 UTC Confidence: 0.86 8 comments
Chronology
  1. Non-compliance period began for third-party evaluation evidence and framework gaps identified during the annual maintenance/procurement cycle.
  2. The auditor identified and formally identified the non-compliance during the GTLSCA auditing close meeting.
  3. GTLSCA completed a comprehensive retrospective third-party risk assessment and evidence collection, ending the described non-compliance period.
  4. GTLSCA completed revisions to internal control assessment processes and follow-up procedures for non-compliant items.
  5. The incident report was closed in the bug as RESOLVED (FIXED).
Thread Activity
  1. Cht representative — Submitted a preliminary incident report stating no objective evidence was found for GTLSCA’s audit and evaluation of third parties with access to CA facilities/systems, citing WebTrust for CA V2.2.2 Criterion 3.1.11.
  2. Cht representative — Submitted a full incident report with the CA CCADB unique ID, described the non-compliance timeline (2024-10-01 to 2025-12-23), and detailed root causes and impact (including that no certificates were misissued).
  3. Cht representative — Noted Chunghwa Telecom was monitoring the bug and had no new information.
  4. Cht representative — Noted Chunghwa Telecom was monitoring the bug and had no new information.
  5. Cht representative — Provided a report closure summary describing remediation completion dates and requesting closure, stating there were no remaining open deliverables.
  6. CCADB representative — Posted a final call for comments and indicated the incident report would be closed approximately 2026-02-12 if no questions were raised.
  7. Mozilla representative — Shared observations that CHT failed to maintain a comprehensive, fully documented third-party evaluation framework per Criterion 3.1.11, and that remediation appeared responsive.
  8. Cht representative — Agreed with Mozilla’s characterization and committed to strengthening continuous compliance assurance, tighter coupling between functions, and clearer ownership/accountability for third-party trust-boundary oversight.
Participants
Cht representative CCADB representative Mozilla representative
Similar Local Cases
#2008788 RESOLVED Self Reported Incident Audit Finding Opened 2026-01-06 · Closed 2026-02-11 · 100% similar
Chunghwa Telecom: Findings in 2025 WebTrust Audit - GTLSCA Audit Incident Report #2 - Domain validation records without the TLS BR version
#2008799 RESOLVED Self Reported Incident Audit Finding Opened 2026-01-06 · Closed 2026-02-19 · 100% similar
Chunghwa Telecom: Findings in 2025 WebTrust Audit - GTLSCA Audit Incident Report #3 - Missing vulnerability scan
#2009045 RESOLVED Self Reported Incident Audit Finding Opened 2026-01-07 · Closed 2026-02-19 · 100% similar
Chunghwa Telecom: Delayed disclosure to Bug 2008788 GTLSCA Audit Incident Report #2 - Domain validation records without the TLS BR version
#1904038 RESOLVED Self Reported Incident Revocation Issue Opened 2024-06-21 · Closed 2025-04-18 · 96% similar
Chunghwa Telecom: “Test Website - Valid" URL disclosed to CCADB is expired
#1916392 RESOLVED Self Reported Incident Revocation Issue Opened 2024-09-03 · Closed 2025-02-12 · 96% similar
Chunghwa Telecom: TLS Certificates Contains two LocalityName Values in SubjectDN by GTLSCA
#1947034 RESOLVED Policy Document Issue Self Reported Incident Opened 2025-02-09 · Closed 2025-04-11 · 95% similar
Chunghwa Telecom: outdated and stale policy documents disclosed to the CCADB
#2012274 RESOLVED Self Reported Incident Certificate Misissuance Revocation Issue Opened 2026-01-24 · Closed 2026-03-08 · 95% similar
Chunghwa Telecom: Issuance of certificate using keys previously reported as compromised
#2009048 RESOLVED Self Reported Incident Audit Finding Opened 2026-01-07 · Closed 2026-02-19 · 89% similar
Chunghwa Telecom: Delayed disclosure to Bug 2008803 GTLSCA Audit Incident Report #4 - Missing evaluation for third parties

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action