Telekom Security: Certificate with invalid FQDN (hyphen prefix)
Deutsche Telekom Security GmbH (Telekom Security) reported that it issued a certificate containing an invalid FQDN: the FQDN started with a hyphen in both the commonName and the SubjectAlternativeName. The issue was discovered by the CA’s internal QA periodical checks of crt.sh lint results, which on 2021-05-16 detected the error. The CA stated that a software bug introduced in 2019 allowed FQDNs starting with a hyphen, and that an Enterprise RA human error produced a template input that was not blocked by the activated linters. As a response, Telekom Security stopped further issuance on 2021-05-16, confirmed the mis-issuance, decided on revocation, and later updated the relevant templates to include certlint and x.509-lint; it then resumed issuance on 2021-05-17. The CA also discussed a separate question raised in the thread about the certificate’s subject serialNumber field and stated it removed the serialNumber from the subjectDN. The CA reported that the hotfix to prevent hyphen-prefixed FQDNs and a software update to centralize linter configuration were deployed on 2021-06-07, and the incident was considered resolved pending any further information requests.
- Internal QA detected that a certificate had been issued with an invalid hyphen-prefixed FQDN.
- Telekom Security stopped further issuance and decided to revoke the erroneous certificate.
- Templates were updated to include certlint and x.509-lint, and issuance was resumed.
- A hotfix and a CA software update to centralize linter configuration were deployed for the PKI service.
- Community commenter — Arnold.Essing reported that Telekom Security issued a certificate with an FQDN starting with a hyphen and said an incident report would follow.
- Community commenter — Arnold.Essing provided a detailed timeline describing how internal QA found the invalid FQDN, how issuance was stopped, how templates were updated with linters, and when issuance was resumed.
- Thisisntrocket representative — Matthias asked about why the revoked certificate included subject:serialNumber and whether it qualifies as metadata under the CPS/baseline requirements.
- Lebihan representative — Michel noted that zlint on crt.sh did not detect the issue and suggested other CAs might also miss it.
- Community commenter — Arnold.Essing explained how serialNumber was used for follow-up certificates and said the field should be removed from the subjectDN to be safe.
- Community commenter — Arnold.Essing stated the serialNumber was removed from the subjectDN and that the hyphen-prevention hotfix would be deployed in week 23.
- Community commenter — Ryan asked for confirmation of how 'week 23' was being measured.
- Community commenter — Arnold.Essing confirmed the change window as 2021-06-07 to 2021-06-09.
- Community commenter — Arnold.Essing reported the hotfix was deployed on 2021-06-07 along with the linter configuration update and said the incident was resolved.
- Mozilla representative — Bwilson indicated they would call the bug up for resolution/closure on or about 11-June-2021 unless more information was needed.