← Telia Company cases
Bugzilla #1689589 Self Reported Incident Security Incident

Telia: Disallowed curve (P-521) in leaf certificate

RESOLVED FIXED Telia Company
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case reports that Telia issued a leaf certificate using an ECDSA key on the P-521 curve, which Telia stated is disallowed by Mozilla’s security policy that permits only P-256 and P-384. Telia said it became aware of the problem from an incident report email from Ben Wilson on 29 Jan 2021, after its ACME solution created the certificate on 25 Jan 2021. Telia reported that its lint checker found the erroneous certificate and that the Telia PKI team evaluated the incident, confirmed corrective actions were required, and investigated similar cases (none were found). Telia stated it revoked the illegal certificate and enhanced its lint alarming rules, and it initiated a bug fix for the ACME server root cause. In later comments, Telia stated it fixed the ACME Server component so it correctly rejects CSRs that request P-521, logging an error when CSR checks fail, and that process improvements for lint error handling were put in place. Mozilla indicated the bug could be closed and scheduled closure unless additional issues were discussed; the bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 20:51 UTC Revised: 2026-06-16 18:16 UTC Confidence: 0.86 4 comments
Chronology
  1. Telia created a certificate using its ACME solution that used the P-521 curve.
  2. Telia’s lint checker identified the erroneous P-521 certificate and sent an incident alarm; Telia received an incident report email from Ben Wilson.
  3. Telia evaluated the incident, revoked the illegal certificate, enhanced lint alarming rules, and initiated a fix for the ACME server.
  4. Telia reported the ACME Server fix was completed to reject P-521 CSRs and that related process improvements were in place.
Thread Activity
  1. Sectigo — Rob Stradling pointed out that crt.sh showed an ECDSA key on P-521 while Mozilla’s policy permits only P-256 and P-384, and referenced a related discussion thread.
  2. Teliasonera representative — Pekka Lahtiharju described how Telia became aware of the issue, provided a timeline of Telia’s investigation, revocation, lint/alarming improvements, and ACME server fix work, and stated Telia had re-linted active Telia SSL certificates.
  3. Teliasonera representative — Pekka Lahtiharju stated Telia fixed the ACME Server bug so it rejects CSRs that use P-521 and added process improvements for lint error handling, and said Telia was ready to close the bug.
  4. Mozilla representative — Ben Wilson said the bug could be closed and scheduled closure on or about 5-Feb-2021 unless additional issues were discussed.
Participants
Sectigo Teliasonera representative Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1896108 RESOLVED Self Reported Incident Certificate Misissuance Opened 2024-05-10 · Closed 2024-09-06 · 89% similar
Telia: Certificates Issued with lower case value in subject:countryName
#1859314 RESOLVED Self Reported Incident Certificate Misissuance Opened 2023-10-16 · Closed 2024-01-26 · 87% similar
Telia: TLS certificates issued in violation of TLS BR v2.0.1
#1920659 RESOLVED Certificate Misissuance Self Reported Incident Opened 2024-09-24 · Closed 2024-12-06 · 87% similar
Telia: S/MIME Certificate issued to expired domain
#1940957 RESOLVED Certificate Misissuance Self Reported Incident Opened 2025-01-10 · Closed 2025-06-20 · 87% similar
Telia: TLS OV certificate with subject countryName and localityName mismatch
#1999296 RESOLVED Security Incident Opened 2025-11-10 · Closed 2025-12-29 · 78% similar
Telia: Findings in 2025 ETSI Audit - Incident Report #1 – Vulnerability management
#1942651 RESOLVED Self Reported Incident Policy Document Issue Opened 2025-01-20 · Closed 2025-02-14 · 77% similar
Sectigo / SSL.com: Late disclosure of updated SSL.com CP/CPS to CCADB
#1965459 RESOLVED Certificate Misissuance Self Reported Incident Opened 2025-05-09 · Closed 2025-10-31 · 77% similar
Telia: S/MIME Misissuance incorrect AIA id-ca-caIssuer http:URI
#1904041 RESOLVED Ca Documents Self Reported Incident Opened 2024-06-21 · Closed 2025-07-01 · 77% similar
NETLOCK: Intermediate CA Certificate not disclosed to CCADB

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action