Chunghwa Telecom: Issuance of certificate using keys previously reported as compromised
Chunghwa Telecom reported an incident involving the issuance of certificates using a private key that had previously been revoked due to key compromise. The CA discovered this issue on January 23, 2026, following a third-party report. An investigation revealed that a total of 8 OV certificates were affected, with 6 still valid at the time of detection. All affected certificates were revoked within 24 hours, and system corrections were implemented to prevent future occurrences. A full incident report was submitted, detailing the root causes and remediation steps taken, including reinstating key compromise validation logic and enhancing compliance tracking.
- Chunghwa Telecom became aware of certificates issued using a previously compromised key.
- Investigation confirmed 8 affected certificates.
- Full incident report submitted detailing the incident and corrective actions.
- Final call for comments on the incident report before closure.
- Cht representative — Preliminary incident report initiated, confirming certificates issued using a compromised key.
- Cht representative — Investigation status update confirmed 8 affected certificates.
- Cht representative — Full incident report submitted detailing the incident and corrective actions.
- Cht representative — Report closure summary provided, detailing root causes and remediation.