← Deutsche Telekom Security GmbH cases
Bugzilla #1703528 Ca Certificate Compliance Certificate Misissuance

Telekom Security: Key Encipherment in two ECC SAN TLS certificates

RESOLVED FIXED Deutsche Telekom Security GmbH
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Deutsche Telekom Security GmbH reported the issuance of two ECC SAN TLS certificates with an incorrect Key Usage of 'Key Encipherment'. The CA discovered the issue during a quality assurance check and revoked the certificates within 24 hours. An incident report was promised following the initial investigation. The root cause was identified as an incorrectly configured template that led to the issuance of the erroneous certificates. The CA has since implemented changes to prevent similar issues, including improvements to their linting processes and template management.

Model: gpt-4o-mini Generated: 2026-06-13 21:21 UTC Revised: 2026-06-16 18:30 UTC Confidence: 0.85 16 comments
Chronology
  1. Two ECC SAN TLS certificates were issued with incorrect Key Usage.
  2. The erroneous certificates were revoked.
Thread Activity
  1. Telekom representative — Two ECC SAN TLS certificates were issued with Key Usage 'Key Encipherment'. The certificates were revoked within 24 hours.
  2. Telekom representative — An incorrect template was referenced, resulting in the issuance of two incorrect ECC SAN TLS certificates.
  3. Community commenter — Request for more details on the change and testing performed.
  4. Telekom representative — The CA software update to centralize the configuration of linters has been deployed.
  5. Telekom representative — The CA software update has been deployed to the remaining CA instance.
Participants
Telekom representative Community commenter
External References
Similar Local Cases
#1711432 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-05-17 · Closed 2023-02-22 · 100% similar
Telekom Security: Certificate with invalid FQDN
#1705791 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-04-16 · Closed 2023-02-22 · 100% similar
Telekom Security: Multiple commonName in certificates
#1957962 RESOLVED Ca Certificate Compliance Opened 2025-04-02 · Closed 2025-07-16 · 91% similar
Telekom Security: QCStatement with http link to PDS
#1875820 RESOLVED Incident Certificate Misissuance Self Reported Incident Opened 2024-01-22 · Closed 2024-08-03 · 90% similar
Telekom Security: TLS certificates with basicConstraints not marked as critical
#1914383 RESOLVED Incident Certificate Misissuance Self Reported Incident Opened 2024-08-22 · Closed 2024-12-11 · 82% similar
Telekom Security: CRL-Entries with wrong CRL Reason Codes
#1718991 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-07-02 · Closed 2024-05-09 · 81% similar
Microsoft PKI Services: Malformed ICAs (Key Usage Malformed)
#1685370 RESOLVED Ca Certificate Compliance Certificate Misissuance Revocation Issue Opened 2021-01-06 · Closed 2023-02-22 · 80% similar
Entrust: Incorrect Business Category Value Discovered in an EV SSL Certificate
#1716123 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-06-12 · Closed 2024-05-25 · 80% similar
e-commerce monitoring GmbH: CN domain not in SAN

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action