← Deutsche Telekom Security GmbH cases
Bugzilla #1703528
Ca Certificate Compliance
Certificate Misissuance
Telekom Security: Key Encipherment in two ECC SAN TLS certificates
RESOLVED
FIXED
Deutsche Telekom Security GmbH
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
Deutsche Telekom Security GmbH reported the issuance of two ECC SAN TLS certificates with an incorrect Key Usage of 'Key Encipherment'. The CA discovered the issue during a quality assurance check and revoked the certificates within 24 hours. An incident report was promised following the initial investigation. The root cause was identified as an incorrectly configured template that led to the issuance of the erroneous certificates. The CA has since implemented changes to prevent similar issues, including improvements to their linting processes and template management.
Chronology
- Two ECC SAN TLS certificates were issued with incorrect Key Usage.
- The erroneous certificates were revoked.
Thread Activity
- Telekom representative — Two ECC SAN TLS certificates were issued with Key Usage 'Key Encipherment'. The certificates were revoked within 24 hours.
- Telekom representative — An incorrect template was referenced, resulting in the issuance of two incorrect ECC SAN TLS certificates.
- Community commenter — Request for more details on the change and testing performed.
- Telekom representative — The CA software update to centralize the configuration of linters has been deployed.
- Telekom representative — The CA software update has been deployed to the remaining CA instance.
Participants
Telekom representative
Community commenter
External References
Similar Local Cases
Telekom Security: Certificate with invalid FQDN
Telekom Security: Multiple commonName in certificates
Telekom Security: QCStatement with http link to PDS
Telekom Security: TLS certificates with basicConstraints not marked as critical
Telekom Security: CRL-Entries with wrong CRL Reason Codes
Microsoft PKI Services: Malformed ICAs (Key Usage Malformed)
Entrust: Incorrect Business Category Value Discovered in an EV SSL Certificate
e-commerce monitoring GmbH: CN domain not in SAN