← Telia Company cases
Bugzilla #1637854 Incident

Telia: AIA CA Issuer field pointing to PEM encoded cert

RESOLVED FIXED Telia Company
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Telia Company reported a compliance issue where the Authority Information Access (AIA) field in their certificates pointed to PEM encoded files instead of the required DER format. The issue was discovered on May 11, 2020, following a user notification. Telia confirmed the incident on May 12, 2020, and promptly replaced all affected CA certificate files with DER encoded versions. The CA continued issuing certificates during this period as the issue did not lead to any misissuance. Telia has since updated their CA creation instructions to prevent future occurrences and implemented monitoring solutions for AIA links to ensure compliance.

Model: gpt-4o-mini Generated: 2026-06-13 20:51 UTC Revised: 2026-06-16 18:15 UTC Confidence: 0.85 13 comments
Chronology
  1. Telia received a notification regarding the incorrect AIA field format.
  2. Telia confirmed the issue and began resolution efforts.
  3. Telia completed the AIA link scan and implemented new monitoring solutions.
Thread Activity
  1. Teliasonera representative — Telia acknowledged the issue and detailed the timeline of actions taken.
  2. Community commenter — Concerns were raised about the adequacy of Telia's testing and monitoring processes.
  3. Teliasonera representative — Telia reported the completion of the AIA link monitoring solutions.
Participants
Teliasonera representative Community commenter
External References
Similar Local Cases
#1722089 RESOLVED Incident Opened 2021-07-23 · Closed 2023-02-22 · 71% similar
SSL.com: Issuance of 3 EV TLS certificates without 2-person validation of the organization information
#1664328 RESOLVED Incident Self Reported Incident Opened 2020-09-10 · Closed 2023-02-22 · 71% similar
GlobalSign: SHA-256 hash algorithm used with ECC P-384 key
#1390991 RESOLVED Ca Certificate Compliance Incident Certificate Misissuance Opened 2017-08-16 · Closed 2023-02-22 · 71% similar
Disig: Non-BR-Compliant Certificate Issuance
#1716902 RESOLVED Incident Opened 2021-06-17 · Closed 2023-02-22 · 70% similar
E-Tugra: Forbidden Domain Validation Method 3.2.2.4.6
#1509002 RESOLVED Policy Document Issue Incident Opened 2018-11-21 · Closed 2023-02-22 · 70% similar
Camerfirma: MULTICERT certificates with a validity period greater than 825 days
#1534429 RESOLVED Incident Self Reported Incident Opened 2019-03-11 · Closed 2023-02-22 · 70% similar
Camerfirma: Multicert SSL CA 001: Insufficient serial number entropy
#1556948 RESOLVED Incident Opened 2019-06-05 · Closed 2023-02-22 · 69% similar
DigiCert: Validation Scope Incident
#1398242 RESOLVED Incident Opened 2017-09-08 · Closed 2023-02-22 · 69% similar
Disig: Non-BR-Compliant OCSP Responders

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action