← Chunghwa Telecom cases
Bugzilla #2025231
Certificate Problem Report
Chunghwa Telecom: Test Website certificate not revoked
RESOLVED
FIXED
Chunghwa Telecom
AI Summary
Chunghwa Telecom faced a compliance issue when a test website certificate was reported as valid instead of revoked. This incident was disclosed by a third party on March 22, 2026, leading to an immediate revocation of the certificate. The root cause was identified as a failure in the automated revocation process, compounded by a lack of monitoring for the test certificates. Following the incident, Chunghwa Telecom enhanced their automation workflow and implemented a monitoring mechanism to prevent future occurrences.
Chronology
- Automated script executed to issue and revoke test certificates.
- Third party reported the certificate status issue.
- Certificate was revoked after the report.
- Final call for comments on the incident report.
Participants
Tsung-Min Kuo
External References
Similar Local Cases
Chunghwa Telecom: “Test Website - Valid" URL disclosed to CCADB is expired
Chunghwa Telecom: OV TLS Server certificate issuance by GTLSCA without proper validation
Chunghwa Telecom: CA Certificates Published in PEM format
Chunghwa Telecom: Issuance of certificate using keys previously reported as compromised
Chunghwa Telecom: Failure to respond to CPR within 24 hours
Chunghwa Telecom: Failure to check restrictive CAA record during Migration
Chunghwa Telecom: Controversial Values within Extension (2.5.29.9, subjectDirectoryAttributes)
Chunghwa Telecom: TLS Certificates Contains two LocalityName Values in SubjectDN by GTLSCA