Telekom Security: CRL also contained unrevoked certificates
Deutsche Telekom Security GmbH reported an incident where a Certificate Revocation List (CRL) incorrectly included unrevoked certificates due to a software bug during a maintenance change. The CA became aware of the issue on July 23, 2020, and took immediate action to rectify the situation, including issuing a new CRL and fixing the erroneous database entries. Although no certificates were misissued, the incident raised concerns about the potential for unrevocation and compatibility issues. The CA committed to revoking the affected certificates after allowing customers time to transition. Ultimately, all 907 affected certificates were revoked by October 1, 2020, and the CA has since implemented measures to prevent similar incidents in the future.
- CA discovered that the CRL contained unrevoked certificates due to a software bug.
- All affected certificates were revoked.
- Telekom representative — Reported the incident and provided a detailed timeline of actions taken.
- Telekom representative — Confirmed that the software bug was fixed and tested.
- Telekom representative — Reported that the last of the affected certificates were revoked.
- Telekom representative — Provided updates on technical measures to prevent future unrevocation.