← Deutsche Telekom Security GmbH cases
Bugzilla #1655698
Certificate Problem Report
Telekom Security: CRL also contained unrevoked certificates
RESOLVED
FIXED
Deutsche Telekom Security GmbH
AI Summary
Deutsche Telekom Security GmbH reported an incident where a Certificate Revocation List (CRL) mistakenly included unrevoked certificates due to a software bug during a maintenance change. The issue was identified on July 23, 2020, and corrective actions were taken, including the issuance of a new CRL. Although no certificates were actually revoked, the erroneous entries raised concerns about potential compatibility issues. The CA has since implemented measures to prevent similar incidents in the future, including software updates and improved QA processes.
Chronology
- Maintenance change began
- Incorrect CRL issued
- Software bug fixed
- Last of the affected certificates revoked
Participants
Arnold Essing
Ryan Sleevi
Stefan Kirch
Jan Völkel
Paul Steinberg
External References
Similar Local Cases
Telekom Security: Key Encipherment in two ECC SAN TLS certificates
Telekom Security: CRL-Entries with wrong CRL Reason Codes
Telekom Security: TLS certificates with basicConstraints not marked as critical
Telekom Security: Multiple commonName in certificates
Telekom Security: Wrong jurisdiction entries in certificates
Telekom Security / DFN: CRL of “DFN-Verein Certification Authority 2“ contains empty revoked certificate list
QuoVadis: EV serialNumber with "none"
KIR S.A.: DV certificates with locality name, organization name and stateOrProvinceName