← Telia Company cases
Bugzilla #1524567
Certificate Misissuance
Telia: invalid IP value in SAN DNS field
RESOLVED
FIXED
Telia Company
AI Summary
Telia Company reported an incident involving three invalid certificates issued in 2016, where IP values were incorrectly stored in the SAN DNS field instead of the SAN IP field. The issue was identified on January 29, 2019, and the certificates were revoked by January 31, 2019. Telia has since implemented automatic testing to prevent similar issues in the future. A mass scan of their certificates revealed additional errors, leading to further revocations and improvements in their certificate issuance process.
Chronology
- Telia informed about invalid certificates
- Certificates revoked
- Preliminary incident report created
- Complete incident report submitted
- Mass zlint scan completed
Participants
pekka.lahtiharju@teliasonera.com
jonathan@titanous.com
wthayer@fastly.com
External References
Similar Local Cases
Telia: Misissued certificate - Invalid OU value "-"
Telia: Misissued certificate - Invalid wildcard format
Telia: Ambiguity on KeyUsage with ECC public key
Telia: misissued certificate - FQDN value incorrectly in SAN rfc822 field
Telia: Misissued certificate - FQDN without domain part (e_dnsname_not_valid_tld)
Telia: Misissued certificate - wrong OrganizationName value "Hair 8 Brains"
Telia: Non-BR-Compliant OCSP Responder
Telia: TLS certificates issued in violation of TLS BR v2.0.1