← Deutsche Telekom Security GmbH cases
Bugzilla #1651611 Self Reported Incident

Telekom Security: ETSI audit finding (2020) about weekly review of configuration changes not being implemented for a specific system

RESOLVED FIXED Deutsche Telekom Security GmbH
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Deutsche Telekom Security GmbH (Telekom Security) reported a compliance finding from a 2020 ETSI audit covering the Network and Certificate System Security Requirements (NCSSR), specifically the requirement for a weekly review of configuration changes. During the audit period (2020-03-23 to 2020-04-01), auditors found that one central network component/appliance was not compliant because neither the standard monitoring solution nor a comparable solution was implemented to fulfill the weekly review requirement. Telekom Security stated that, due to the system’s limited customizability, the standard monitoring client could not be installed, and an alternative process was later implemented. Telekom Security performed retrospective checks using log data and reported that there were no findings of unauthorized changes, and that no other systems were affected. A weekly review process by qualified personnel was established on 2020-04-15, and auditors later inspected the alternative solution on 2020-07-08 and determined it fulfilled NCSSR v1.3. Telekom Security also explained that they delayed posting the bug report and said they would not wait for future incident disclosures (or at least preliminary reports). The bug was resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:20 UTC Revised: 2026-06-16 18:27 UTC Confidence: 0.86 8 comments
Chronology
  1. An ETSI audit identified a non-conformity: weekly review of configuration changes was not implemented for a specific central network component/appliance.
  2. Telekom Security established a weekly review of configuration changes by qualified personnel.
  3. Auditors inspected the alternative solution and determined it fulfilled NCSSR v1.3.
  4. The bug was intended to be closed after follow-up questions.
Thread Activity
  1. Community commenter — Opened the bug describing the ETSI audit finding and Telekom Security’s remediation steps, including retrospective review and establishing a weekly review process.
  2. Mozilla representative — Asked for clarification on the incident timeline, whether changes were unauthorized, why reporting was delayed, and requested more incident-report detail per Mozilla’s template.
  3. Community commenter — Clarified that changes were authorized (the issue was that they would not be discovered in a weekly review), described the affected system, and explained why operations were continued.
  4. Community commenter — Provided a revised incident report based on the new template with a more detailed timeline and additional context.
  5. Community commenter — Requested details about how log data is maintained and trusted, and asked about controls supporting prompt reporting and script/script-disabling risks.
  6. Community commenter — Explained that logs are sent to a central tamper-proof log server, described protections for the automated script, and stated the core team would not wait to disclose future incident reports.
  7. Mozilla representative — Indicated no further questions and requested closing the bug on or about 27-Jan-2021.
Participants
Telekom representative Mozilla representative Community commenter
Similar Local Cases
#1675314 RESOLVED Self Reported Incident Opened 2020-11-04 · Closed 2023-02-22 · 94% similar
Telekom Security: Wrong jurisdiction entries in certificates
#1825780 RESOLVED Incident Self Reported Incident Opened 2023-03-31 · Closed 2023-07-05 · 87% similar
Telekom Security: Improper use of a domain validation method
#1875820 RESOLVED Incident Certificate Misissuance Self Reported Incident Opened 2024-01-22 · Closed 2024-08-03 · 86% similar
Telekom Security: TLS certificates with basicConstraints not marked as critical
#1914383 RESOLVED Incident Certificate Misissuance Self Reported Incident Opened 2024-08-22 · Closed 2024-12-11 · 77% similar
Telekom Security: CRL-Entries with wrong CRL Reason Codes
#1715455 RESOLVED Self Reported Incident Opened 2021-06-09 · Closed 2024-01-10 · 76% similar
Let's Encrypt: certificate lifetimes 90 days plus one second
#1740493 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-11-10 · Closed 2023-02-22 · 76% similar
Sectigo: Failure to block disallowed LDH labels in domain names
#1658792 RESOLVED Self Reported Incident Opened 2020-08-12 · Closed 2023-02-22 · 75% similar
Entrust: Invalid data in State/Province Field
#1716123 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-06-12 · Closed 2024-05-25 · 75% similar
e-commerce monitoring GmbH: CN domain not in SAN

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action