← Chunghwa Telecom cases
Bugzilla #2012274 Self Reported Incident Certificate Misissuance Revocation Issue

Chunghwa Telecom: Issuance of certificate using keys previously reported as compromised

RESOLVED FIXED Chunghwa Telecom
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Chunghwa Telecom reported an incident involving the issuance of certificates using a private key that had previously been revoked due to key compromise. The CA discovered this issue on January 23, 2026, following a third-party report. An investigation revealed that a total of 8 OV certificates were affected, with 6 still valid at the time of detection. All affected certificates were revoked within 24 hours, and system corrections were implemented to prevent future occurrences. A full incident report was submitted, detailing the root causes and remediation steps taken, including reinstating key compromise validation logic and enhancing compliance tracking.

Model: gpt-4o-mini Generated: 2026-06-13 21:37 UTC Revised: 2026-06-16 18:11 UTC Confidence: 0.85 14 comments
Chronology
  1. Chunghwa Telecom became aware of certificates issued using a previously compromised key.
  2. Investigation confirmed 8 affected certificates.
  3. Full incident report submitted detailing the incident and corrective actions.
  4. Final call for comments on the incident report before closure.
Thread Activity
  1. Cht representative — Preliminary incident report initiated, confirming certificates issued using a compromised key.
  2. Cht representative — Investigation status update confirmed 8 affected certificates.
  3. Cht representative — Full incident report submitted detailing the incident and corrective actions.
  4. Cht representative — Report closure summary provided, detailing root causes and remediation.
Participants
Cht representative CCADB representative
External References
Similar Local Cases
#1956910 RESOLVED Certificate Misissuance Opened 2025-03-27 · Closed 2025-07-16 · 100% similar
Chunghwa Telecom: OV TLS Server certificate issuance by GTLSCA without proper validation
#1916392 RESOLVED Self Reported Incident Revocation Issue Opened 2024-09-03 · Closed 2025-02-12 · 99% similar
Chunghwa Telecom: TLS Certificates Contains two LocalityName Values in SubjectDN by GTLSCA
#1904038 RESOLVED Self Reported Incident Revocation Issue Opened 2024-06-21 · Closed 2025-04-18 · 98% similar
Chunghwa Telecom: “Test Website - Valid" URL disclosed to CCADB is expired
#1951415 RESOLVED Certificate Misissuance Delayed Revocation Opened 2025-03-03 · Closed 2025-05-08 · 98% similar
Chunghwa Telecom: Failure to check restrictive CAA record during Migration
#2008788 RESOLVED Self Reported Incident Audit Finding Opened 2026-01-06 · Closed 2026-02-11 · 95% similar
Chunghwa Telecom: Findings in 2025 WebTrust Audit - GTLSCA Audit Incident Report #2 - Domain validation records without the TLS BR version
#2008803 RESOLVED Self Reported Incident Audit Finding Opened 2026-01-06 · Closed 2026-02-12 · 95% similar
Chunghwa Telecom: Findings in 2025 WebTrust Audit - GTLSCA Audit Incident Report #4 - Missing evaluation for third parties
#2009045 RESOLVED Self Reported Incident Audit Finding Opened 2026-01-07 · Closed 2026-02-19 · 95% similar
Chunghwa Telecom: Delayed disclosure to Bug 2008788 GTLSCA Audit Incident Report #2 - Domain validation records without the TLS BR version
#2008799 RESOLVED Self Reported Incident Audit Finding Opened 2026-01-06 · Closed 2026-02-19 · 94% similar
Chunghwa Telecom: Findings in 2025 WebTrust Audit - GTLSCA Audit Incident Report #3 - Missing vulnerability scan

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action