← Telia Company cases
Bugzilla #1612332 Self Incident Disclosure

Telia: Ambiguity on KeyUsage with ECC public key

RESOLVED FIXED Telia Company
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Telia reported a problem involving ECDSA certificates whose Key Usage (KU) values combined “key encipherment” and “data encryption,” which Telia stated does not make sense and should be treated as misissuance. Telia said it became aware of the issue when it received an email from Secom (Tadahiko Ito) about five possibly incorrect certificates with improper KU values, and Telia verified the five certificates. Telia started a revocation process for two still-active certificates and investigated why the problem existed; Telia found the error had been fixed in 2018 but that these older certificates were undetected because Telia’s zlint setup did not log this KU combination as a problem. Telia stated it created and used a better scanner than zlint, scanned all active Telia SSL certificates, and found three additional similar problem certificates, then started revocation for them as well. Telia reported that the problematic certificates were revoked, and Mozilla later indicated the remediation was complete. The bug was resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 20:51 UTC Revised: 2026-06-16 18:15 UTC Confidence: 0.86 4 comments
Chronology
  1. Telia received an email from Secom identifying five possibly incorrect ECDSA certificates with improper Key Usage values and verified them.
  2. Telia investigated the cause, identified that the issue was not detected by its zlint configuration, and began remediation including revocation and scanner improvements.
  3. Telia scanned all active certificates with a new scanner, found additional problematic certificates, and initiated revocation for them.
  4. Telia reported that all problematic certificates listed in the case were revoked.
  5. Mozilla/participants stated that questions were answered and remediation was complete.
Thread Activity
  1. Teliasonera representative — Telia described the KU issue, verified five certificates from Secom’s email, started revocation for two active certificates, investigated detection gaps with zlint, created a better scanner, scanned active certificates, found three more problematic certificates, and stated Telia stopped issuing this KU combination in 2018.
  2. Teliasonera representative — Telia stated that all problematic certificates listed above are revoked.
  3. Community commenter — Ryan Sleevi noted it was an old issue, referenced an IETF document in the editor’s queue, and pointed to a zlint issue as the resolution pending finalization.
  4. Fastly representative — Wayne Thayer stated it appears all questions have been answered and remediation is complete.
Participants
Teliasonera representative Community commenter Fastly representative
Similar Local Cases
#1551372 RESOLVED Self Incident Disclosure Opened 2019-05-14 · Closed 2023-02-22 · 69% similar
Telia: "Some-State" in stateOrProvinceName
#1524050 RESOLVED Certificate Misissuance Opened 2019-01-30 · Closed 2023-02-22 · 68% similar
Telia: Misissued certificate - invalid dnsName
#1528263 RESOLVED Certificate Misissuance Opened 2019-02-15 · Closed 2023-02-22 · 67% similar
Telia: Misissued certificate - Invalid wildcard format
#1528261 RESOLVED Certificate Misissuance Opened 2019-02-15 · Closed 2023-02-22 · 62% similar
Telia: Misissued certificate - FQDN without domain part (e_dnsname_not_valid_tld)
#1528264 RESOLVED Certificate Misissuance Opened 2019-02-15 · Closed 2023-02-22 · 62% similar
Telia: Misissued certificate - Invalid OU value "-"
#1524567 RESOLVED Certificate Misissuance Opened 2019-02-01 · Closed 2023-02-22 · 61% similar
Telia: invalid IP value in SAN DNS field
#1738207 RESOLVED Certificate Misissuance Opened 2021-10-28 · Closed 2023-02-22 · 59% similar
Telia: Issued three precertificates with non-NIST EC curve
#1637854 RESOLVED Incident Opened 2020-05-14 · Closed 2023-02-22 · 58% similar
Telia: AIA CA Issuer field pointing to PEM encoded cert

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action