← Deutsche Telekom Security GmbH cases
Bugzilla #1711432 Ca Certificate Compliance Certificate Misissuance

Telekom Security: Certificate with invalid FQDN (hyphen prefix)

RESOLVED FIXED Deutsche Telekom Security GmbH
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Deutsche Telekom Security GmbH (Telekom Security) reported that it issued a certificate containing an invalid FQDN: the FQDN started with a hyphen in both the commonName and the SubjectAlternativeName. The issue was discovered by the CA’s internal QA periodical checks of crt.sh lint results, which on 2021-05-16 detected the error. The CA stated that a software bug introduced in 2019 allowed FQDNs starting with a hyphen, and that an Enterprise RA human error produced a template input that was not blocked by the activated linters. As a response, Telekom Security stopped further issuance on 2021-05-16, confirmed the mis-issuance, decided on revocation, and later updated the relevant templates to include certlint and x.509-lint; it then resumed issuance on 2021-05-17. The CA also discussed a separate question raised in the thread about the certificate’s subject serialNumber field and stated it removed the serialNumber from the subjectDN. The CA reported that the hotfix to prevent hyphen-prefixed FQDNs and a software update to centralize linter configuration were deployed on 2021-06-07, and the incident was considered resolved pending any further information requests.

Model: gpt-5.4-nano Generated: 2026-06-13 21:23 UTC Revised: 2026-06-16 18:32 UTC Confidence: 0.90 10 comments
Chronology
  1. Internal QA detected that a certificate had been issued with an invalid hyphen-prefixed FQDN.
  2. Telekom Security stopped further issuance and decided to revoke the erroneous certificate.
  3. Templates were updated to include certlint and x.509-lint, and issuance was resumed.
  4. A hotfix and a CA software update to centralize linter configuration were deployed for the PKI service.
Thread Activity
  1. Community commenter — Arnold.Essing reported that Telekom Security issued a certificate with an FQDN starting with a hyphen and said an incident report would follow.
  2. Community commenter — Arnold.Essing provided a detailed timeline describing how internal QA found the invalid FQDN, how issuance was stopped, how templates were updated with linters, and when issuance was resumed.
  3. Thisisntrocket representative — Matthias asked about why the revoked certificate included subject:serialNumber and whether it qualifies as metadata under the CPS/baseline requirements.
  4. Lebihan representative — Michel noted that zlint on crt.sh did not detect the issue and suggested other CAs might also miss it.
  5. Community commenter — Arnold.Essing explained how serialNumber was used for follow-up certificates and said the field should be removed from the subjectDN to be safe.
  6. Community commenter — Arnold.Essing stated the serialNumber was removed from the subjectDN and that the hyphen-prevention hotfix would be deployed in week 23.
  7. Community commenter — Ryan asked for confirmation of how 'week 23' was being measured.
  8. Community commenter — Arnold.Essing confirmed the change window as 2021-06-07 to 2021-06-09.
  9. Community commenter — Arnold.Essing reported the hotfix was deployed on 2021-06-07 along with the linter configuration update and said the incident was resolved.
  10. Mozilla representative — Bwilson indicated they would call the bug up for resolution/closure on or about 11-June-2021 unless more information was needed.
Participants
Telekom representative Thisisntrocket representative Lebihan representative Community commenter Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1705791 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-04-16 · Closed 2023-02-22 · 100% similar
Telekom Security: Multiple commonName in certificates
#1703528 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-04-07 · Closed 2023-02-22 · 100% similar
Telekom Security: Key Encipherment in two ECC SAN TLS certificates
#1875820 RESOLVED Incident Certificate Misissuance Self Reported Incident Opened 2024-01-22 · Closed 2024-08-03 · 94% similar
Telekom Security: TLS certificates with basicConstraints not marked as critical
#1705187 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-04-14 · Closed 2023-02-22 · 94% similar
KIR S.A.: CN domain not in SAN
#1716123 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-06-12 · Closed 2024-05-25 · 94% similar
e-commerce monitoring GmbH: CN domain not in SAN
#1957962 RESOLVED Ca Certificate Compliance Opened 2025-04-02 · Closed 2025-07-16 · 87% similar
Telekom Security: QCStatement with http link to PDS
#1532436 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2019-03-04 · Closed 2023-02-22 · 87% similar
Chunghwa Telecom: Test certificate with unregistered domain name
#1662382 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2020-09-01 · Closed 2023-02-22 · 86% similar
GDCA: Incorrect Value in organizationName Field

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action