← Telia Company cases
Bugzilla #1612332 Certificate Misissuance

Telia: Ambiguity on KeyUsage with ECC public key

RESOLVED FIXED Telia Company
AI Summary

Telia Company addressed an issue regarding ECDSA certificates that had improper Key Usage values, specifically 'key encipherment' and 'data encryption'. The problem was first reported on January 28, 2020, when Telia was alerted to five potentially incorrect certificates. Following an investigation, Telia confirmed that two of these certificates were still active and initiated a revocation process. All problematic certificates were ultimately revoked by February 5, 2020. The root cause was identified as a limitation in their scanning tool, zlint, which did not log this specific Key Usage combination as a problem. Telia has since improved their scanning processes to prevent future occurrences.

Model: gpt-4o-mini Generated: 2026-06-13 20:51 UTC Confidence: 1.00
Chronology
  1. Telia received a report about five certificates with improper Key Usage values.
  2. Telia investigated the issue and confirmed the error was previously fixed in 2018.
  3. Telia's own scanner identified three additional problematic certificates.
  4. All problematic certificates were revoked.
Participants
pekka.lahtiharju@teliasonera.com ryan.sleevi@gmail.com wthayer@fastly.com
Similar Local Cases
#1528263 RESOLVED Certificate Misissuance Opened 2019-02-15 · Closed 2023-02-22 · 74% similar
Telia: Misissued certificate - Invalid wildcard format
#1524567 RESOLVED Certificate Misissuance Opened 2019-02-01 · Closed 2023-02-22 · 68% similar
Telia: invalid IP value in SAN DNS field
#1528264 RESOLVED Certificate Misissuance Opened 2019-02-15 · Closed 2023-02-22 · 67% similar
Telia: Misissued certificate - Invalid OU value "-"
#1528261 RESOLVED Certificate Misissuance Opened 2019-02-15 · Closed 2023-02-22 · 60% similar
Telia: Misissued certificate - FQDN without domain part (e_dnsname_not_valid_tld)
#1528259 RESOLVED Certificate Misissuance Opened 2019-02-15 · Closed 2023-02-22 · 58% similar
Telia: misissued certificate - FQDN value incorrectly in SAN rfc822 field
#1828105 RESOLVED Certificate Misissuance Opened 2023-04-14 · Closed 2023-06-30 · 58% similar
Telia: Misissued certificate - wrong OrganizationName value "Hair 8 Brains"
#1552586 RESOLVED Certificate Misissuance Opened 2019-05-17 · Closed 2023-02-22 · 56% similar
GlobalSign: 4 Misissued certificates with invalid CN
#1426247 RESOLVED Certificate Misissuance Opened 2017-12-19 · Closed 2023-02-22 · 55% similar
Telia: Non-BR-Compliant OCSP Responder

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action