← Chunghwa Telecom cases
Bugzilla #2012274 Certificate Problem Report

Chunghwa Telecom: Issuance of certificate using keys previously reported as compromised

RESOLVED FIXED Chunghwa Telecom
AI Summary

On January 23, 2026, Chunghwa Telecom (CHT) was notified of certificates issued using a private key that had previously been revoked due to key compromise. An investigation revealed that a missing system configuration allowed the issuance of certificates with compromised keys. A total of 8 affected OV certificates were identified, with 6 still valid at the time of detection. All affected certificates were revoked within 24 hours, and corrective measures were implemented to prevent future occurrences. CHT has committed to maintaining compliance with TLS Baseline Requirements and enhancing their validation processes.

Model: gpt-4o-mini Generated: 2026-06-13 21:37 UTC Confidence: 1.00
Chronology
  1. Received third-party notification regarding compromised key usage.
  2. Investigation completed, identifying 8 affected certificates.
  3. Full incident report submitted.
  4. Action items for remediation completed.
  5. Incident report closure summary provided.
Participants
Tsung-Min Kuo
Similar Local Cases
#2025231 RESOLVED Certificate Problem Report Opened 2026-03-23 · Closed 2026-04-24 · 61% similar
Chunghwa Telecom: Test Website certificate not revoked
#1904038 RESOLVED Certificate Problem Report Opened 2024-06-21 · Closed 2025-04-18 · 60% similar
Chunghwa Telecom: “Test Website - Valid" URL disclosed to CCADB is expired
#1956910 RESOLVED Certificate Problem Report Opened 2025-03-27 · Closed 2025-07-16 · 60% similar
Chunghwa Telecom: OV TLS Server certificate issuance by GTLSCA without proper validation
#2005567 RESOLVED Certificate Problem Report Opened 2025-12-11 · Closed 2026-02-03 · 60% similar
Chunghwa Telecom: CA Certificates Published in PEM format
#2005762 RESOLVED Certificate Problem Report Opened 2025-12-12 · Closed 2026-02-05 · 59% similar
Chunghwa Telecom: Failure to respond to CPR within 24 hours
#1951415 RESOLVED Certificate Problem Report Opened 2025-03-03 · Closed 2025-05-08 · 56% similar
Chunghwa Telecom: Failure to check restrictive CAA record during Migration
#1899466 RESOLVED Certificate Problem Report Opened 2024-05-29 · Closed 2024-09-13 · 50% similar
Chunghwa Telecom: Controversial Values within Extension (2.5.29.9, subjectDirectoryAttributes)
#1916392 RESOLVED Certificate Problem Report Opened 2024-09-03 · Closed 2025-02-12 · 50% similar
Chunghwa Telecom: TLS Certificates Contains two LocalityName Values in SubjectDN by GTLSCA

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action