Telekom Security: Wrong jurisdiction entries in EV certificates
Deutsche Telekom Security GmbH (Telekom Security) disclosed that six EV certificates were issued with incorrect jurisdiction entries for a customer’s Spanish subsidiary. The CA said it became aware of the issue through its internal auditor during a regular check on 2020-11-02. The CA stated that a software bug prevented the customer from entering the correct jurisdiction information in its customer master data, so a workaround was used: the required information was provided via a different channel and validated, while the mandatory fields in the master data were temporarily filled with the German parent company’s jurisdiction information. The CA reported that the final certificates therefore contained the wrong jurisdiction information. The CA said it stopped issuance of EV certificates, revoked the six certificates on 2020-11-03, evaluated whether additional certificates were affected, and later resumed EV issuance for German and Swiss subjects after a safeguarding phase and additional RA-Team sensitization and RA-GUI improvements. Mozilla indicated the matter could be closed and scheduled closure for 7-Apr-2021. The bug is resolved as FIXED.
- Internal auditor identified six EV certificates with unusual/incorrect jurisdiction entries during a regular check.
- The CA revoked the six EV certificates and confirmed the planned revocation after management review.
- The CA completed evaluation for additional affected certificates and resumed EV issuance for German and Swiss subjects with RA-Team and RA-GUI changes.
- Telekom representative — Reported that six EV certificates were issued with incorrect jurisdiction entries, that they were revoked the next working day and never used, and that a detailed incident report would follow.
- Telekom representative — Provided the incident details and timeline, including the software bug/workaround that led to wrong jurisdiction data in the certificates, the decision to stop EV issuance, revocation, evaluation for further affected certificates, and later resumption with RA-Team sensitization and RA-GUI improvements.
- Community commenter — Asked about why the incident was not caught by controls required by Ballot SC30 and questioned the detection by the internal auditor versus the RA.
- Telekom representative — Explained the role of the free-text field, the RA validation process, and how a technical expert’s incorrect assumption led to the workaround being approved.
- Mozilla representative — Stated the matter could be closed and scheduled closure on 7-Apr-2021 unless otherwise heard.