Chunghwa Telecom: Delayed audit disclosure for GTLSCA
Categories
(CA Program :: CA Certificate Compliance, task)
Tracking
(Not tracked)
People
(Reporter: tmkuo, Assigned: tmkuo)
Details
(Whiteboard: [ca-compliance] [audit-delay])
Attachments
(4 files, 6 obsolete files)
Preliminary Incident Report
Summary
- Incident description: The annual audit report of GTLSCA was obtained on 2025/12/13 and make the audit report publicly available. GTLSCA CA team was originally planned to provide WebTrust Seal URLs to its Root CA, Chunghwa Telecom (CHT), for uploading to CCADB by the end of December. Due to GTLSCA’s has been planning to terminate services in mid-2026, based on the CA owner, Ministry of Digital Affairs, assessment, it’s not necessary to renewal the seal for this year. This cause CHT can not get the WebTrust seal URLs and complete the CCADB upload by the end of December.
Based on the supervisory responsibility of the Root CA, CHT believe that GTLSCA, having issued TLS certificates during this year’s audit period (2024/10/1 – 2025/9/30), should not skip applying for the CPA CANADA audit seals. By the end of December, CHT completed an emergency negotiation with GTLSCA’s auditor. We expect to obtain the CPA CANADA seals and complete the upload by the end of January.
- Relevant policies: CCADB 5.2.2 WebTrust
Unqualified WebTrust audit statements provided by licensed WebTrust practitioners MUST have a WebTrust Seal. Qualified WebTrust audit statements provided by licensed WebTrust practitioners SHOULD have a WebTrust Seal. Whether unqualified or qualified, CAs enter the URL of the WebTrust Seal into the CCADB, and upon saving the record, the CCADB automatically converts the URL to point to the corresponding PDF file via integration with CPA Canada. ...
- Source of incident disclosure: Self Reported.
| Assignee | ||
Comment 1•8 months ago
|
||
| Assignee | ||
Comment 2•8 months ago
|
||
| Assignee | ||
Comment 3•8 months ago
|
||
| Assignee | ||
Comment 4•8 months ago
|
||
Updated•7 months ago
|
Updated•7 months ago
|
| Assignee | ||
Comment 5•7 months ago
|
||
| Assignee | ||
Comment 6•7 months ago
|
||
| Assignee | ||
Comment 7•7 months ago
|
||
| Assignee | ||
Comment 8•7 months ago
|
||
Full Incident Report
Summary
- CA Owner CCADB unique ID: A006506
- Incident description: The annual audit report of GTLSCA was obtained on 2025/12/13 and make the audit report publicly available. GTLSCA CA team was originally planned to provide WebTrust Seal URLs to its Root CA, Chunghwa Telecom (CHT), for uploading to CCADB by the end of December. Due to GTLSCA’s has been planning to terminate services in mid-2026, based on the CA owner, Ministry of Digital Affairs, assessment, it’s not necessary to renewal the seal for this year. This cause CHT can not get the WebTrust seal URLs and complete the CCADB upload by the end of December.
Based on the supervisory responsibility of the Root CA, CHT believe that GTLSCA, having issued TLS certificates during this year’s audit period (2024/10/1 – 2025/9/30), should not skip applying for the CPA CANADA audit seals. By the end of December, CHT completed an emergency negotiation with GTLSCA’s auditor. We expect to obtain the CPA CANADA seals and complete the upload by the end of January.
- Timeline summary:
- Non-compliance start date: 2025-12-22
- Non-compliance identified date: 2025-12-31
- Non-compliance end date: Expected to end the non-compliance before 2026-01-31.
- Relevant policies: CCADB 5.2.2 WebTrust
Unqualified WebTrust audit statements provided by licensed WebTrust practitioners MUST have a WebTrust Seal. Qualified WebTrust audit statements provided by licensed WebTrust practitioners SHOULD have a WebTrust Seal. Whether unqualified or qualified, CAs enter the URL of the WebTrust Seal into the CCADB, and upon saving the record, the CCADB automatically converts the URL to point to the corresponding PDF file via integration with CPA Canada. ...
- Source of incident disclosure: Self Reported.
Impact
- Total number of certificates: N/A
- Total number of "remaining valid" certificates: N/A
- Affected certificate types: N/A
- Incident heuristic: The potential impact of this incident may affect the trustworthiness of all TLS certificates issued by GTLSCA, as well as the CA's compliance commitment to browser.
- Was issuance stopped in response to this incident, and why or why not?: As there were no certificates misissued, issuance was not stopped. However, this CA has already stopped issuing TLS certificates in early March 2025.
- Analysis:
- Additional considerations:
Timeline
All times are UTC+8.
Fourth Quarter of 2024: The CA Owner, MODA, engages KPMG to conduct an external audit of GTLSCA.
2025-11-11: Complete the annual audit for the GTLSCA period.
2025-11-18: The auditor scheduled a closing meeting with GTLSCA Team.
2025-11-20 ~ 2025-12-08: MODA initiates the stamping process for the audit report and Assertion Management.
2025-12-13: GTLSCA Team get the annual Audit Report of GTLSCA.
2025-12-19: A request for the WebTrust for CA Seal URLs was made by the GTLSCA Team to the Auditor and MODA.
2025-12-21: MODA informed the GTLSCA Team that due to the cessation of GTLSCA's issuance, they will not apply for the seal this year.
2025-12-22: The GTLSCA Team informed the Root CA, CHT, of the potential risk of a delay in the audit report upload. [start of the non-compliance]
2025-12-26 ~ 2025-12-30: The Auditor confirmed that the audit seal is still available for application. After numerous discussions with MODA and the auditor regarding compliance, CHT, with consent from MODA, proceeded to enter into the seal application process with the auditor.
2025-12-31
- 10:44: The Auditor informed that due to the Christmas and New Year holidays, CPA CANADA will not process CHT's audit seal application until at least January 5, 2026. [Identify of the non-compliance]
- 14:16: The Auditor provides Audit Explanation Letter.
2026-01-06
- The Auditor notified CHT that CPA Canada has confirmed receipt of the seal application and is currently reviewing it. They advised that, based on previous cases, the audit seal URLs is typically obtained within 1 to 2 weeks.
2026-01-06 ~ Before the end of January 2026
- Given that the delay in the auditor seal application is a certainty, CHT's procurement unit requires the procurement process with the Auditor to be thoroughly completed, a procedure which is time-consuming and will take approximately 1-2 weeks.
2026-01-31
- Expected to get the audit seal URLs and complete the upload before this date.
Related Incidents
| Bug | Date | Description |
|---|---|---|
| 1917224 | 2024-09-06 | Delayed Annual Audit Report 2024. |
Root Cause Analysis
Contributing Factor 1: The CA Owner did not promptly discuss the compliance matters of the audit seal with the CA team.
- Description: The CA Owner determined that obtaining the CPA CANADA audit seal was not necessary this year due to the cessation of GTLSCA's issuance.
- Timeline:
Fourth Quarter of 2024: The CA Owner, MODA, engages KPMG to conduct an external audit of GTLSCA.
2025-12-21: MODA informed the GTLSCA Team that due to the cessation of GTLSCA's issuance, they will not apply for the seal this year.
2025-12-22: The GTLSCA Team informed CHT of the potential risk of a delay in the audit report upload. - Detection: The CA Owner MODA informed the CA Team on December 21 regarding not apply for the audit seal this year. As a result, CHT gets the audit report but do not have the CPA CANADA approved seal URLs, and were unable to upload them to CCADB before the end of December 2025.
- Interaction with other factors:
(a) A more timely warning from the GTLSCA team to the Root CA team could have prevented the upload delay. The situation was compounded by the CA Owner's assessment that the audit seal application was unnecessary, a conclusion based on the fact that they were not responsible for the audit seal upload via CCADB.
(b) This was the starting point of the incident. Initially, MODA likely assumed that since this CA no longer provided services externally, the corresponding annual audit seal was naturally unnecessary. They overlooked the fundamental principle that "as long as a CA certificate remains valid, it must continuously meet its compliance commitments within the trust ecosystem."
Contributing Factor 2: The direct commissioning of the ICA audit by the ICA Owner creates a challenge for the Root CA to promptly ascertain if the final audit documents align with its requirements.
- Description: This direct commissioning bypasses a critical quality assurance checkpoint from the Root CA. This arrangement also creates a structural gap in the oversight process, isolating the Root CA from the audit's preliminary stages and brings a significant risk of non-conformity, as deviations from Root CA standards may only be discovered upon final submission.
- Timeline:
Fourth Quarter of 2024: The CA Owner, MODA, engages KPMG to conduct an external audit of GTLSCA.
2025-11-18: The auditor scheduled a closing meeting with GTLSCA Team.
2025-11-20 ~ 2025-12-08: MODA initiates the stamping process for the audit report and Assertion Management.
2025-12-13: GTLSCA Team get the annual Audit Report of GTLSCA. - Detection: When the audit was contracted out by the Root CA, it would also typically be possible to confirm at this point whether the audit seal application has been completed.
- Interaction with other factors:
(a) This causes the Root CA to lack visibility and control throughout the process. The Root CA acts more like a "final acceptor" than a "process manager," and is therefore unable to identify issues in a timely manner.
(b) Although the ICA/GTLSCA team is on the front line, they may not have realized that the failure to apply for the seal was a "red flag" issue that required an immediate alert to Root CA management. This reflects that the team's judgment on how a single incident can impact the bigger picture needs to be strengthened.
Lessons Learned
- What went well: Out of a commitment to community responsibility and compliance, CHT had a contingency plan: had CPA CANADA confirmed that the audit seal was unattainable, CHT would have proceeded with the mass revocation of all EE certificates issued by GTLSCA as well as the CA certificate of GTLSCA.
- What didn’t go well: The ICA team should have been more proactive in issuing an alert, tracking the audit seal application's progress, or aligning with the Auditor on its status earlier.
- Where we got lucky: N/A
- Additional: N/A
Action Items
| Action Item | Kind | Corresponding Root Cause(s) | Evaluation Criteria | Due Date | Status |
|---|---|---|---|---|---|
| Annual Compliance Checklist | Prevent | Root Cause # 1 | Revise and enhance the process | 2026-01-09 | Completed |
| Establishing a Mandatory Communication and Review Mechanism | Mitigate | Root Cause # 1 & #2 | Establishing Checkpoints for Communication and Review | 2026-01-12 | Completed |
| The commissioning of all future ICA audits should be centralized under the Root CA. | Prevent | Root Cause # 2 | ICA Contract Amendments | 2026-01-12 | Completed |
| Audit Kick-off Meeting (Participants: CA Owner, Root CA and ICA team) | Prevent | Root Cause # 1 & # 2 | Revise and enhance the process | 2026-01-23 | Ongoing |
This report will be updated upon receipt of the audit seal URLs.
| Assignee | ||
Comment 9•7 months ago
|
||
Chunghwa Telecom is monitoring this bug for comments and questions. We have no new information at the moment.
| Assignee | ||
Comment 10•7 months ago
|
||
We have obtained the CPA CANADA seal URLs on 2026/1/30 and completed the upload on 2026/1/31. Therefore, we update the Full Incident Report.
Full Incident Report
Summary
- CA Owner CCADB unique ID: A006506
- Incident description: The annual audit report of GTLSCA was obtained on 2025/12/13 and make the audit report publicly available. GTLSCA CA team was originally planned to provide WebTrust Seal URLs to its Root CA, Chunghwa Telecom (CHT), for uploading to CCADB by the end of December. Due to GTLSCA’s has been planning to terminate services in mid-2026, based on the CA owner, Ministry of Digital Affairs, assessment, it’s not necessary to renewal the seal for this year. This cause CHT can not get the WebTrust seal URLs and complete the CCADB upload by the end of December.
Based on the supervisory responsibility of the Root CA, CHT believe that GTLSCA, having issued TLS certificates during this year’s audit period (2024/10/1 – 2025/9/30), should not skip applying for the CPA CANADA audit seals. By the end of December, CHT completed an emergency negotiation with GTLSCA’s auditor. We have obtained the CPA CANADA seal URLs on 2026/1/30 and completed the upload on 2026/1/31.
- Timeline summary:
- Non-compliance start date: 2025-12-22
- Non-compliance identified date: 2025-12-31
- Non-compliance end date: 2026-01-31.
- Relevant policies: CCADB 5.2.2 WebTrust
Unqualified WebTrust audit statements provided by licensed WebTrust practitioners MUST have a WebTrust Seal. Qualified WebTrust audit statements provided by licensed WebTrust practitioners SHOULD have a WebTrust Seal. Whether unqualified or qualified, CAs enter the URL of the WebTrust Seal into the CCADB, and upon saving the record, the CCADB automatically converts the URL to point to the corresponding PDF file via integration with CPA Canada. ...
- Source of incident disclosure: Self Reported.
Impact
- Total number of certificates: N/A
- Total number of "remaining valid" certificates: N/A
- Affected certificate types: N/A
- Incident heuristic: The potential impact of this incident may affect the trustworthiness of all TLS certificates issued by GTLSCA, as well as the CA's compliance commitment to browser.
- Was issuance stopped in response to this incident, and why or why not?: As there were no certificates misissued, issuance was not stopped. However, this CA has already stopped issuing TLS certificates in early March 2025.
- Analysis:
- Additional considerations:
Timeline
All times are UTC+8.
Fourth Quarter of 2024: The CA Owner, MODA, engages KPMG to conduct an external audit of GTLSCA.
2025-11-11: Complete the annual audit for the GTLSCA period.
2025-11-18: The auditor scheduled a closing meeting with GTLSCA Team.
2025-11-20 ~ 2025-12-08: MODA initiates the stamping process for the audit report and Assertion Management.
2025-12-13: GTLSCA Team get the annual Audit Report of GTLSCA.
2025-12-19: A request for the WebTrust for CA Seal URLs was made by the GTLSCA Team to the Auditor and MODA.
2025-12-21: MODA informed the GTLSCA Team that due to the cessation of GTLSCA's issuance, they will not apply for the seal this year.
2025-12-22: The GTLSCA Team informed the Root CA, CHT, of the potential risk of a delay in the audit report upload. [start of the non-compliance]
2025-12-26 ~ 2025-12-30: The Auditor confirmed that the audit seal is still available for application. After numerous discussions with MODA and the auditor regarding compliance, CHT, with consent from MODA, proceeded to enter into the seal application process with the auditor.
2025-12-31
- 10:44: The Auditor informed that due to the Christmas and New Year holidays, CPA CANADA will not process CHT's audit seal application until at least January 5, 2026. [Identify of the non-compliance]
- 14:16: The Auditor provides Audit Explanation Letter.
2026-01-06
- The Auditor notified CHT that CPA Canada has confirmed receipt of the seal application and is currently reviewing it. They advised that, based on previous cases, the audit seal URLs is typically obtained within 1 to 2 weeks.
2026-01-06 ~ Before the end of January 2026
- Given that the delay in the auditor seal application is a certainty, CHT's procurement unit requires the procurement process with the Auditor to be thoroughly completed, a procedure which is time-consuming and will take approximately 1-2 weeks.
2026-01-30
- Obtained the CPA CANADA seal URLs.
2026-01-31
- Completed the seal URLs upload. [End of of the non-compliance]
Related Incidents
| Bug | Date | Description |
|---|---|---|
| 1917224 | 2024-09-06 | Delayed Annual Audit Report 2024. |
Root Cause Analysis
Contributing Factor 1: The CA Owner did not promptly discuss the compliance matters of the audit seal with the CA team.
- Description: The CA Owner determined that obtaining the CPA CANADA audit seal was not necessary this year due to the cessation of GTLSCA's issuance.
- Timeline:
Fourth Quarter of 2024: The CA Owner, MODA, engages KPMG to conduct an external audit of GTLSCA.
2025-12-21: MODA informed the GTLSCA Team that due to the cessation of GTLSCA's issuance, they will not apply for the seal this year.
2025-12-22: The GTLSCA Team informed CHT of the potential risk of a delay in the audit report upload. - Detection: The CA Owner MODA informed the CA Team on December 21 regarding not apply for the audit seal this year. As a result, CHT gets the audit report but do not have the CPA CANADA approved seal URLs, and were unable to upload them to CCADB before the end of December 2025.
- Interaction with other factors:
(a) A more timely warning from the GTLSCA team to the Root CA team could have prevented the upload delay. The situation was compounded by the CA Owner's assessment that the audit seal application was unnecessary, a conclusion based on the fact that they were not responsible for the audit seal upload via CCADB.
(b) This was the starting point of the incident. Initially, MODA likely assumed that since this CA no longer provided services externally, the corresponding annual audit seal was naturally unnecessary. They overlooked the fundamental principle that "as long as a CA certificate remains valid, it must continuously meet its compliance commitments within the trust ecosystem."
Contributing Factor 2: The direct commissioning of the ICA audit by the ICA Owner creates a challenge for the Root CA to promptly ascertain if the final audit documents align with its requirements.
- Description: This direct commissioning bypasses a critical quality assurance checkpoint from the Root CA. This arrangement also creates a structural gap in the oversight process, isolating the Root CA from the audit's preliminary stages and brings a significant risk of non-conformity, as deviations from Root CA standards may only be discovered upon final submission.
- Timeline:
Fourth Quarter of 2024: The CA Owner, MODA, engages KPMG to conduct an external audit of GTLSCA.
2025-11-18: The auditor scheduled a closing meeting with GTLSCA Team.
2025-11-20 ~ 2025-12-08: MODA initiates the stamping process for the audit report and Assertion Management.
2025-12-13: GTLSCA Team get the annual Audit Report of GTLSCA. - Detection: When the audit was contracted out by the Root CA, it would also typically be possible to confirm at this point whether the audit seal application has been completed.
- Interaction with other factors:
(a) This causes the Root CA to lack visibility and control throughout the process. The Root CA acts more like a "final acceptor" than a "process manager," and is therefore unable to identify issues in a timely manner.
(b) Although the ICA/GTLSCA team is on the front line, they may not have realized that the failure to apply for the seal was a "red flag" issue that required an immediate alert to Root CA management. This reflects that the team's judgment on how a single incident can impact the bigger picture needs to be strengthened.
Lessons Learned
- What went well: Out of a commitment to community responsibility and compliance, CHT had a contingency plan: had CPA CANADA confirmed that the audit seal was unattainable, CHT would have proceeded with the mass revocation of all EE certificates issued by GTLSCA as well as the CA certificate of GTLSCA.
- What didn’t go well: The ICA team should have been more proactive in issuing an alert, tracking the audit seal application's progress, or aligning with the Auditor on its status earlier.
- Where we got lucky: N/A
- Additional: N/A
Action Items
| Action Item | Kind | Corresponding Root Cause(s) | Evaluation Criteria | Due Date | Status |
|---|---|---|---|---|---|
| Annual Compliance Checklist | Prevent | Root Cause # 1 | Revise and enhance the process | 2026-01-09 | Completed |
| Establishing a Mandatory Communication and Review Mechanism | Mitigate | Root Cause # 1 & #2 | Establishing Checkpoints for Communication and Review | 2026-01-12 | Completed |
| The commissioning of all future ICA audits should be centralized under the Root CA. | Prevent | Root Cause # 2 | ICA Contract Amendments | 2026-01-12 | Completed |
| Audit Kick-off Meeting (Participants: CA Owner, Root CA and ICA team) | Prevent | Root Cause # 1 & # 2 | Revise and enhance the process | 2026-01-23 | Completed |
| Assignee | ||
Comment 11•7 months ago
|
||
| Assignee | ||
Comment 12•7 months ago
|
||
| Assignee | ||
Comment 13•7 months ago
|
||
| Assignee | ||
Comment 14•6 months ago
|
||
Chunghwa Telecom is monitoring this bug for comments and questions. The CCADB case regarding the annual audit seal URLs update for GTLSCA has been approved and closed. We will post the closure report in days.
| Assignee | ||
Comment 15•6 months ago
|
||
Report Closure Summary
- Incident description: The annual WebTrust audit report for GTLSCA, covering the audit period from 2024‑10‑01 to 2025‑09‑30, was obtained on 2025‑12‑13. Due to an initial assessment by the CA Owner that renewal of the CPA CANADA WebTrust audit seal was unnecessary following the planned service termination of GTLSCA, the audit seal application was not initiated in time. As a result, the Root CA, CHT, was unable to upload the required WebTrust seal URLs to CCADB by the end of December 2025, resulting in a non‑compliance with CCADB policy requirements. By the end of December, CHT completed an emergency negotiation with GTLSCA’s auditor, then we have obtained the CPA CANADA seal URLs on 2026-01-30 and completed the upload on 2026-01-31.
- Incident Root Cause(s):
(a) The CA Owner did not promptly discuss the compliance matters of the audit seal with the CA team: insufficient and untimely communication between the CA Owner and the CA team regarding the continued compliance obligation to obtain and upload the audit seal while the CA certificate remained valid.
(b) The direct commissioning of the ICA audit by the ICA Owner creates a challenge for the Root CA to promptly ascertain if the final audit documents align with its requirements: a structural oversight gap caused by the audit being directly commissioned by the ICA Owner, which limited the Root CA’s visibility and ability to verify audit completeness, including confirmation of audit seal application, prior to final report delivery. - Remediation description: Upon identifying the compliance gap, CHT initiated emergency coordination with the CA Owner, and the auditor to proceed with the audit seal application. Despite delays caused by holiday periods and procurement procedures, the CPA CANADA WebTrust seal URLs were successfully obtained on 2026‑01‑30 and uploaded to CCADB on 2026‑01‑31, thereby ending the period of non‑compliance. In parallel, CHT implemented process improvements, including revising annual compliance checklists, establishing mandatory communication and review checkpoints among the CA Owner, Root CA, and ICA teams, and formalizing audit kick‑off meetings to ensure early alignment on compliance requirements.
- Commitment summary: CHT commits to maintaining continuous compliance with CCADB and WebTrust requirements for all subordinate CAs whose certificates remain valid, regardless of issuance status or service termination plans. The Root CA has strengthened governance, communication, and oversight mechanisms to ensure audit seal application and CCADB disclosures are completed accurately and on time, preventing recurrence of similar incidents. Chunghwa Telecom will ensure continuous adherence to Web PKI standards.
All Action Items disclosed in this report have been completed as described, and we request its closure.
Comment 16•6 months ago
|
||
This is a final call for comments or questions on this Incident Report.
Otherwise, it will be closed on approximately 2026-02-19.
Updated•6 months ago
|
Description
•