← Deutsche Telekom Security GmbH cases
Bugzilla #1675314 Self Reported Incident

Telekom Security: Wrong jurisdiction entries in EV certificates

RESOLVED FIXED Deutsche Telekom Security GmbH
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Deutsche Telekom Security GmbH (Telekom Security) disclosed that six EV certificates were issued with incorrect jurisdiction entries for a customer’s Spanish subsidiary. The CA said it became aware of the issue through its internal auditor during a regular check on 2020-11-02. The CA stated that a software bug prevented the customer from entering the correct jurisdiction information in its customer master data, so a workaround was used: the required information was provided via a different channel and validated, while the mandatory fields in the master data were temporarily filled with the German parent company’s jurisdiction information. The CA reported that the final certificates therefore contained the wrong jurisdiction information. The CA said it stopped issuance of EV certificates, revoked the six certificates on 2020-11-03, evaluated whether additional certificates were affected, and later resumed EV issuance for German and Swiss subjects after a safeguarding phase and additional RA-Team sensitization and RA-GUI improvements. Mozilla indicated the matter could be closed and scheduled closure for 7-Apr-2021. The bug is resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:21 UTC Revised: 2026-06-16 18:29 UTC Confidence: 0.90 5 comments
Chronology
  1. Internal auditor identified six EV certificates with unusual/incorrect jurisdiction entries during a regular check.
  2. The CA revoked the six EV certificates and confirmed the planned revocation after management review.
  3. The CA completed evaluation for additional affected certificates and resumed EV issuance for German and Swiss subjects with RA-Team and RA-GUI changes.
Thread Activity
  1. Telekom representative — Reported that six EV certificates were issued with incorrect jurisdiction entries, that they were revoked the next working day and never used, and that a detailed incident report would follow.
  2. Telekom representative — Provided the incident details and timeline, including the software bug/workaround that led to wrong jurisdiction data in the certificates, the decision to stop EV issuance, revocation, evaluation for further affected certificates, and later resumption with RA-Team sensitization and RA-GUI improvements.
  3. Community commenter — Asked about why the incident was not caught by controls required by Ballot SC30 and questioned the detection by the internal auditor versus the RA.
  4. Telekom representative — Explained the role of the free-text field, the RA validation process, and how a technical expert’s incorrect assumption led to the workaround being approved.
  5. Mozilla representative — Stated the matter could be closed and scheduled closure on 7-Apr-2021 unless otherwise heard.
Participants
Telekom representative Community commenter Mozilla representative
External References
Similar Local Cases
#1825780 RESOLVED Incident Self Reported Incident Opened 2023-03-31 · Closed 2023-07-05 · 95% similar
Telekom Security: Improper use of a domain validation method
#1875820 RESOLVED Incident Certificate Misissuance Self Reported Incident Opened 2024-01-22 · Closed 2024-08-03 · 94% similar
Telekom Security: TLS certificates with basicConstraints not marked as critical
#1651611 RESOLVED Self Reported Incident Opened 2020-07-09 · Closed 2023-02-22 · 94% similar
Telekom Security: Finding in 2020 ETSI-Audit regarding weekly review of changes to configurations
#1914383 RESOLVED Incident Certificate Misissuance Self Reported Incident Opened 2024-08-22 · Closed 2024-12-11 · 80% similar
Telekom Security: CRL-Entries with wrong CRL Reason Codes
#1649963 RESOLVED Self Reported Incident Opened 2020-07-02 · Closed 2023-02-22 · 78% similar
Atos: Incorrect OCSP Delegated Responder Certificate
#1649951 RESOLVED Self Reported Incident Revocation Issue Opened 2020-07-02 · Closed 2023-02-22 · 77% similar
DigiCert: Incorrect OCSP Delegated Responder Certificate
#1575022 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2019-08-19 · Closed 2023-02-22 · 77% similar
Sectigo: EV SSL Certificates with incorrect subject details.
#1658792 RESOLVED Self Reported Incident Opened 2020-08-12 · Closed 2023-02-22 · 77% similar
Entrust: Invalid data in State/Province Field

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action