Telia: Failure to disclose Unconstrained Intermediate within 7 Days
Telia Company failed to disclose a new self-signed root certificate, 'Telia Root CA v2', within the required timeframe after its creation. This issue was identified by Mozilla, prompting Telia to provide an incident report detailing the timeline and actions taken. Telia clarified that the new root was intended to replace older roots and had been audited, but they misunderstood the disclosure requirements. Following discussions, Telia disclosed the root certificate in the Common CA Database (CCADB) and committed to ensuring compliance with Mozilla's policies in the future. The case has been resolved with the necessary disclosures made.
- Telia created a new self-signed root certificate.
- Mozilla opened a bug regarding the failure to disclose the new root certificate.
- Telia disclosed the new root certificate in CCADB.
- Telia submitted a full incident report and remediation was confirmed complete.
- Community commenter — TeliaSonera has one or more intermediate certificates not disclosed via CCADB.
- Teliasonera representative — This is not an incident; the new root certificate is not yet trusted.
- Fastly representative — It appears that all questions have been answered and remediation is complete.