← Deutsche Telekom Security GmbH cases
Bugzilla #1703528
Certificate Problem Report
Telekom Security: Key Encipherment in two ECC SAN TLS certificates
RESOLVED
FIXED
Deutsche Telekom Security GmbH
AI Summary
Deutsche Telekom Security GmbH identified an issue where two ECC SAN TLS certificates were incorrectly issued with the Key Usage set to 'Key Encipherment'. The certificates were revoked within 24 hours of issuance. The problem arose during a change to extend CT logs, which led to an incorrect template being referenced. An internal investigation revealed that the error was due to a misconfiguration in the production environment, which was not present in the test environment. The CA has since implemented measures to prevent such occurrences in the future.
Chronology
- Two ECC SAN TLS certificates issued
- Certificates revoked
Participants
Arnold Essing
Ryan Sleevi
External References
Similar Local Cases
Telekom Security: CRL also contained unrevoked certificates
Telekom Security: Multiple commonName in certificates
Telekom Security: Wrong jurisdiction entries in certificates
Telekom Security: CRL-Entries with wrong CRL Reason Codes
Telekom Security: TLS certificates with basicConstraints not marked as critical
Telekom Security: Improper use of a domain validation method
SwissSign: CP/CPS certificate profile issue
Microsoft PKI Services: Underscore in SAN