← Telia Company cases
Bugzilla #1689589 Certificate Problem Report

Telia: Disallowed curve (P-521) in leaf certificate

RESOLVED FIXED Telia Company
AI Summary

Telia Company issued a leaf certificate using the disallowed P-521 elliptic curve, which violates Mozilla's security policies. The issue was identified through an incident report and subsequent internal audits. Telia took immediate corrective actions, including revoking the problematic certificate and enhancing their lint checking processes to prevent future occurrences. The bug in the ACME server that allowed this issue was fixed, ensuring that invalid certificate signing requests are now properly rejected.

Model: gpt-4o-mini Generated: 2026-06-13 20:51 UTC Confidence: 0.95
Chronology
  1. Certificate created using Telia ACME solution
  2. Telia received incident report regarding the disallowed curve
  3. Incident evaluated and corrective actions initiated
  4. Bug in ACME server fixed to reject invalid CSRs
Participants
Rob Stradling Pekka Lahtiharju Ben Wilson
Similar Local Cases
#1896553 RESOLVED Certificate Problem Report Opened 2024-05-14 · Closed 2025-02-12 · 57% similar
Telia: Delayed revocation of seven (7) certificates related to incident 1896108
#1863122 RESOLVED Certificate Problem Report Opened 2023-11-04 · Closed 2024-01-10 · 55% similar
CFCA: CRL Error
#1896462 RESOLVED Certificate Problem Report Opened 2024-05-13 · Closed 2024-06-01 · 55% similar
Digicert: Preview certificate uploaded to CCADB instead of the actual certificate
#1738207 RESOLVED Certificate Problem Report Opened 2021-10-28 · Closed 2023-02-22 · 55% similar
Telia: Issued three precertificates with non-NIST EC curve
#1931615 RESOLVED Certificate Problem Report Opened 2024-11-15 · Closed 2024-12-03 · 54% similar
SSL.com: Entrust API and CAA checking
#1925106 RESOLVED Certificate Problem Report Opened 2024-10-16 · Closed 2025-07-22 · 54% similar
DigiCert: Incorrect CP listed in CCADB
#1952519 RESOLVED Certificate Problem Report Opened 2025-03-07 · Closed 2025-05-08 · 53% similar
Microsec: Inconsistent Disclosure of S/MIME BR Audit Information in CCADB
#1614311 RESOLVED Certificate Problem Report Opened 2020-02-10 · Closed 2024-06-30 · 52% similar
Telia: Two Intermediate CA certificates not listed in audit report

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action