← Chunghwa Telecom cases
Bugzilla #2009045 Delayed Revocation

Chunghwa Telecom: Delayed disclosure to Bug 2008788 GTLSCA Audit Incident Report #2 - Domain validation records without the TLS BR version

RESOLVED FIXED Chunghwa Telecom
AI Summary

Chunghwa Telecom experienced a delayed disclosure incident related to an audit finding from the GTLSCA annual audit report, which was received on December 13, 2025. The audit finding, concerning domain validation records lacking the TLS BR version, was not disclosed within the required 72-hour timeframe, as mandated by CCADB Policy 5.2. This oversight was identified on January 6, 2026, after a third-party notification. The CA has since initiated corrective actions, including mandatory training on CCADB policies and the implementation of an audit-finding monitoring dashboard.

Model: gpt-4o-mini Generated: 2026-06-13 21:37 UTC Confidence: 0.95
Chronology
  1. Start of non-compliance due to missed disclosure window
  2. Non-compliance identified
  3. Non-compliance ended
Participants
Tsung-Min Kuo
Related Bugzilla IDs Mentioned
Similar Local Cases
#2009048 RESOLVED Delayed Revocation Opened 2026-01-07 · Closed 2026-02-19 · 72% similar
Chunghwa Telecom: Delayed disclosure to Bug 2008803 GTLSCA Audit Incident Report #4 - Missing evaluation for third parties
#1959278 RESOLVED Delayed Revocation Opened 2025-04-08 · Closed 2025-06-24 · 58% similar
Chunghwa Telecom: Delayed revocation for bug 1951415
#1903066 RESOLVED Delayed Revocation Opened 2024-06-17 · Closed 2025-02-12 · 49% similar
Chunghwa Telecom: Delayed Revocation with Controversial Extension (2.5.29.9, SubjectDirectoryAttributes)
#1892419 RESOLVED Delayed Revocation Opened 2024-04-19 · Closed 2025-02-12 · 48% similar
Chunghwa Telecom: Delayed Revocation Due to GTLSCA EKU Misissuance
#1752636 RESOLVED Delayed Revocation Opened 2022-01-28 · Closed 2023-02-22 · 40% similar
SSL.com: Delayed revocation of 53 certificates affected by bug #1750631
#1945389 RESOLVED Delayed Revocation Opened 2025-02-02 · Closed 2025-05-01 · 40% similar
HARICA: delayed revocation for bug 1943596
#1862082 RESOLVED Delayed Revocation Opened 2023-10-30 · Closed 2023-12-14 · 40% similar
D-Trust: Delay beyond 5 days in revoking misissued certificate
#2011855 RESOLVED Delayed Revocation Opened 2026-01-22 · Closed 2026-05-11 · 40% similar
Firmaprofesional: Delayed revocation of TLS certificates affected by bug #2009941

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action