← Deutsche Telekom Security GmbH cases
Bugzilla #1651487 Delayed Revocation

Telekom Security: Delayed Revocations of Sub-CA certificates

RESOLVED FIXED Deutsche Telekom Security GmbH
AI Summary

Deutsche Telekom Security GmbH faced delays in revoking Sub-CA certificates due to the significant impact on over 230,000 users. The revocation process was complicated by the need to reissue certificates under a new Issuing CA, which was projected to take up to five months. The migration to the new CA was initiated, and updates were provided regularly. All affected certificates were eventually revoked, and key material destruction was completed in the presence of an external auditor.

Model: gpt-4o-mini Generated: 2026-06-13 21:19 UTC Confidence: 0.95
Chronology
  1. Initial report of delayed revocation due to user impact.
  2. Revocation of all EE certificates from 'TeleSec PKS CA 8'.
  3. Revocation of remaining certificates from four affected CAs.
  4. Key material destruction for remaining CAs completed.
  5. Closure of the case anticipated.
Participants
Arnold Essing jan.voelkel@telekom.de stefan.kirch@telekom.de ryan.sleevi@gmail.com bwilson@mozilla.com
Similar Local Cases
#1877388 RESOLVED Delayed Revocation Opened 2024-01-30 · Closed 2025-03-14 · 57% similar
Telekom Security: Revocation delay for TLS certificates with basicConstraints not marked as critical
#1903066 RESOLVED Delayed Revocation Opened 2024-06-17 · Closed 2025-02-12 · 49% similar
Chunghwa Telecom: Delayed Revocation with Controversial Extension (2.5.29.9, SubjectDirectoryAttributes)
#1886532 RESOLVED Delayed Revocation Opened 2024-03-20 · Closed 2025-02-21 · 48% similar
Entrust: Delayed revocation of EV TLS certificates with missing cPSuri
#1891251 RESOLVED Delayed Revocation Opened 2024-04-12 · Closed 2024-06-01 · 48% similar
FIRMAPROFESIONAL: Delayed leaf revocation
#1947691 RESOLVED Delayed Revocation Opened 2025-02-12 · Closed 2025-08-19 · 47% similar
NETLOCK: Bug 1891331 replacement - delayed revocation -
#1892419 RESOLVED Delayed Revocation Opened 2024-04-19 · Closed 2025-02-12 · 46% similar
Chunghwa Telecom: Delayed Revocation Due to GTLSCA EKU Misissuance
#1889062 RESOLVED Delayed Revocation Opened 2024-04-02 · Closed 2025-04-03 · 45% similar
GDCA: Delayed revocation of SSL/TLS certificates with Non-critical Basic Constraints
#1692535 RESOLVED Delayed Revocation Opened 2021-02-12 · Closed 2023-02-22 · 42% similar
Camerfirma: Delayed revocations of certificates issued by old CAs with an RSA modulus size of 2047 bits

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action