← Deutsche Telekom Security GmbH cases
Bugzilla #1705791
Ca Certificate Compliance
Certificate Misissuance
Telekom Security: Multiple commonName in certificates
RESOLVED
FIXED
Deutsche Telekom Security GmbH
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
This case involves Deutsche Telekom Security GmbH, which discovered multiple 'commonName' fields in several certificates, potentially violating Mozilla's CA policies. The issue was reported on April 16, 2021, and the CA acknowledged the problem on April 19, 2021. They updated their issuance system to prevent further issuance of certificates with multiple 'commonName' fields and committed to revoke the affected certificates by April 24, 2021. The CA has since completed the revocation and updated their internal rules to better assess anomalies in certificate issuance.
Chronology
- Bug reported regarding multiple commonName fields in certificates.
- Deutsche Telekom Security acknowledged the issue and began investigating.
- System changes implemented to prevent issuance of certificates with multiple commonNames.
- All affected certificates were revoked.
Thread Activity
- Lebihan representative — Reported certificates with multiple commonName fields.
- Telekom representative — Acknowledged the notification and began investigation.
- Dfn-cert representative — Confirmed system changes to prevent future issuance of multiple commonNames.
- Dfn-cert representative — All affected certificates have been revoked.
Participants
Lebihan representative
Community commenter
Telekom representative
Dfn-cert representative
External References
Similar Local Cases
Telekom Security: Certificate with invalid FQDN
Telekom Security: Key Encipherment in two ECC SAN TLS certificates
Telekom Security: TLS certificates with basicConstraints not marked as critical
Telekom Security: QCStatement with http link to PDS
e-commerce monitoring GmbH: CN domain not in SAN
KIR S.A.: CN domain not in SAN
Telekom Security: CRL-Entries with wrong CRL Reason Codes
Disig: Non-BR-Compliant Certificate Issuance