Chunghwa Telecom: Incomplete disclosure of CRL URLs in CCADB
Categories
(CA Program :: CA Certificate Compliance, task)
Tracking
(Not tracked)
People
(Reporter: tmkuo, Assigned: tmkuo)
Details
(Whiteboard: [ca-compliance] [disclosure-failure])
Preliminary Incident Report
Summary
- Incident description: The URLs disclosed in CCADB are not comprehensive for the CRLs of our CAs.
- Relevant policies: CCADB Policy, Section 6.2
For any unexpired and unrevoked CA certificate disclosed to the CCADB, CA Owners MUST disclose, in a JSON array, the complete set of distinct HTTP URLs appearing in the crlDistributionPoints extension of the unexpired certificates issued by that CA. The disclosed URLs MUST match exactly as they appear in the issued certificates.
- Source of incident disclosure: Third party reported.
The Full Incident Report will be submitted before 2026-07-27 8:25 AM (UTC+8).
Updated•1 month ago
|
| Assignee | ||
Updated•1 month ago
|
| Assignee | ||
Comment 1•1 month ago
|
||
Full Incident Report
Summary
-
CA Owner CCADB unique ID: A010946
-
Incident description: A third party reported a potential compliance issue regarding our CA's adherence to the CCADB Policy, which requires CA Owners to disclose, in JSON array format, the complete set of distinct HTTP URLs appearing in the cRLDistributionPoints extension of all unexpired and unrevoked certificates, exactly as they appear in those certificates.
Upon investigation, we confirmed that the "JSON Array of All Full CRL URLs" field for this CA contained only http://repository.tls.hinet.net/crl/OVCA-complete.crl, while certificates issued under this CA contained additional partitioned CRL URLs. These partitioned CRL URLs should have been disclosed in the "JSON Array of Partitioned CRLs" field; however, they were not properly stored in the CCADB record, resulting in incomplete CRL URL disclosure.
-
Timeline summary:
- Non-compliance start date: 2025-07-15
- Non-compliance identified date: 2026-07-13
- Non-compliance end date: 2026-07-13
-
Relevant policies: CCADB Policy, Section 6.2
For any unexpired and unrevoked CA certificate disclosed to the CCADB, CA Owners MUST disclose, in a JSON array, the complete set of distinct HTTP URLs appearing in the crlDistributionPoints extension of the unexpired certificates issued by that CA. The disclosed URLs MUST match exactly as they appear in the issued certificates.
- Source of incident disclosure: Third party reported.
Impact
- Total number of certificates: N/A
- Total number of "remaining valid" certificates: N/A
- Affected certificate types: N/A
- Incident heuristic: Compliance and disclosure representation issue.
- Was issuance stopped in response to this incident, and why or why not?: As there were no certificates misissued, issuance was not stopped.
- Analysis: N/A
- Additional considerations:
Timeline
All times are UTC+8.
2025-07-15
- CCADB Policy 2.0 released. [start of the non-compliance]
2026-03-20
- CCADB Policy 2.1 released.
2026-07-13
- 8:25 A third party reported a potential compliance issue regarding the CRL URLs disclosed in CCADB.
- 10:30-11:40 Investigation initiated and confirmed that the issue violated the requirements of CCADB Policy, Section 6.2. [Identify of the non-compliance]
- 11:27 Internal Tracking: Setting up Bugzilla Initial Reporting and Full Incident Reporting timelines and expected completion dates
- 11:40-14:54 Conduct a comprehensive review of all certificates issued under our CAs to identify and confirm all partitioned CRL URLs.
- 15:13 Updated the "JSON Array of Partitioned CRLs" field for the affected CA in CCADB to include the missing partitioned CRL URLs. [End of the non-compliance]
2026-07-15 Preliminary incident report published in Bugzilla.
2026-07-26 Full incident report published on Bugzilla.
Related Incidents
| Bug | Date | Description |
|---|---|---|
| 2007089 | 2025-12-19 | subordinate certificates have not published the complete CRL address in CCADB. |
| 2007216 | 2025-12-19 | CRL Disclosure in CCADB Mismatch with Issued Certificates. |
| 2007116 | 2025-12-19 | CRL URL Disclosure. |
| 2049012 | 2026-06-19 | Inaccuracy in CRL URL in CCADB. |
| 2055047 | 2026-07-14 | Incomplete disclosure of CRL URLs in CCADB. |
| 2054849 | 2026-07-14 | Incorrect CRL URL in CCADB. |
| 2055250 | 2026-07-15 | Incomplete Disclosure of CRL URLs. |
| 2055775 | 2026-07-17 | Incomplete CRL Disclosure in CCADB. |
Root Cause Analysis
Contributing Factor #1: Lack of secondary check review controls for CCADB updates
- Description: The affected CA's partitioned CRL URLs were not completely registered in the CCADB "JSON Array of Partitioned CRLs" field. The disclosure process relied on manual data entry and review by a single individual, and no independent verification was performed to confirm that all CRL Distribution Point URLs present in issued certificates were accurately reflected in the corresponding CCADB disclosure fields.
- Timeline: 2025-2026
- Detection: The issue remained undetected until a third party reported the discrepancy on 2026-07-13. Following internal investigation and verification, the missing partitioned CRL URLs were added to the CCADB record on the same day, resolving the non-compliance.
- Interaction with other factors: The absence of an independent review process was compounded by the lack of a reconciliation procedure between issued certificates and CCADB disclosures. These factors collectively allowed the inaccurate disclosure to persist until external discovery.
- Root Cause Analysis methodology used: 5 Whys methodology was conducted.
Lessons Learned
- What went well: Following notification from the third party, the incident was promptly escalated and investigated. The team quickly reviewed certificates issued under the affected CA, identified the missing partitioned CRL URLs, and corrected the CCADB disclosure on the same day. The established incident-response process enabled timely containment and reporting.
- What didn’t go well: The CCADB disclosure process depended on a single-person review and lacked an independent review requirement. As a result, the corresponding CCADB disclosure was not verified against certificate contents, allowing the omission to persist undetected until reported by a third-party.
- Where we got lucky: The issue involved only CCADB disclosure accuracy and did not affect certificate issuance, certificate validity, revocation processing, or relying-party security.
- Additional: As a result of this incident, CHT reviewed all certificates issued under its affected CAs to identify and verify partitioned CRL URLs and updated the corresponding CCADB records where necessary. In addition, CHT is implementing a mandatory four-eyes review process and strengthening compliance awareness related to CCADB disclosures to reduce the likelihood of similar incidents recurring.
Action Items
| Action Item | Kind | Corresponding Root Cause(s) | Evaluation Criteria | Due Date | Status |
|---|---|---|---|---|---|
| Updated the "JSON Array of Partitioned CRLs" field for the affected CA in CCADB to include the missing partitioned CRL URLs. | Mitigate | Root Cause # 1 | CRL URLs disclosed in CCADB match CRL URLs in certificate. | 2026-07-13 | Complete |
| Implement a mandatory four-eyes review process for all CCADB disclosures, changes and reviews. | Prevent | Root Cause # 1 | The action will be considered effective when all future CCADB updates undergo documented four-eyes review, and a verification of the affected CA records confirms that all CRL Distribution Point URLs contained in issued certificates are accurately disclosed in the corresponding CCADB fields. No discrepancies are identified during post-implementation compliance reviews. | 2026-07-31 | Ongoing |
| Training and awareness | Prevent | Root Cause # 1 | Provide training to development and operations teams on CCADB compliance requirements and the importance of complete validation logging. | 2026-08-07 | Ongoing |
Appendix
| Affected CA | Old Entry (JSON Array of Partitioned CRLs) | New Corrected Entry |
|---|---|---|
| HiPKI OV TLS CA - G1 | ["http://repository.tls.hinet.net/crl/OVCA-3000-1.crl","http://repository.tls.hinet.net/crl/OVCA-6000-1.crl","http://repository.tls.hinet.net/crl/OVCA-8000-1.crl"] |
| Assignee | ||
Comment 2•1 month ago
|
||
Action Items Update
| Action Item | Kind | Corresponding Root Cause(s) | Evaluation Criteria | Due Date | Status |
|---|---|---|---|---|---|
| Updated the "JSON Array of Partitioned CRLs" field for the affected CA in CCADB to include the missing partitioned CRL URLs. | Mitigate | Root Cause # 1 | CRL URLs disclosed in CCADB match CRL URLs in certificate. | 2026-07-13 | Complete |
| Implement a mandatory four-eyes review process for all CCADB disclosures, changes and reviews. | Prevent | Root Cause # 1 | The action will be considered effective when all future CCADB updates undergo documented four-eyes review, and a verification of the affected CA records confirms that all CRL Distribution Point URLs contained in issued certificates are accurately disclosed in the corresponding CCADB fields. No discrepancies are identified during post-implementation compliance reviews. | 2026-07-30 | Complete |
| Training and awareness | Prevent | Root Cause # 1 | Provide training to development and operations teams on CCADB compliance requirements and the importance of complete validation logging. | 2026-07-31 | Complete |
| Assignee | ||
Comment 3•29 days ago
|
||
Chunghwa Telecom is monitoring this bug for comments and questions. We have no new information at the moment.
| Assignee | ||
Comment 4•22 days ago
|
||
Report Closure Summary
- Incident description: A third party identified that the CCADB disclosure for the affected CA did not contain the complete set of CRL Distribution Point URLs appearing in issued certificates. Specifically, several partitioned CRL URLs were missing from the CCADB "JSON Array of Partitioned CRLs" field, resulting in incomplete CRL URL disclosure under CCADB Policy Section 6.2.
- Incident Root Cause(s): The disclosure process relied on manual data entry and review by a single individual. No independent verification or reconciliation process existed to ensure that all CRL Distribution Point URLs contained in issued certificates were accurately reflected in the corresponding CCADB disclosure fields. This lack of secondary review controls allowed the omission to remain undetected until reported by a third party.
- Remediation description: CHT completed a comprehensive review of the affected CA certificates, identified all missing partitioned CRL URLs, and updated the corresponding CCADB records on the same day the issue was confirmed. In addition, a mandatory four-eyes review process has been implemented for all CCADB disclosures, changes, and reviews, and compliance awareness training has been completed for relevant personnel. All corrective and preventive actions have been completed.
- Commitment summary: CHT is committed to maintaining accurate and complete CCADB disclosures and to ensuring continued compliance with CCADB requirements. The newly established four-eyes review process and enhanced compliance awareness measures will be applied to all future CCADB updates to prevent similar disclosure discrepancies from recurring.
All Action Items disclosed in this report have been completed as described, and we request its closure.
Comment 5•22 days ago
|
||
This is a final call for comments or questions on this Incident Report.
Otherwise, it will be closed on approximately 2026-08-21.
Updated•15 days ago
|
Description
•