← Telia Company cases
Bugzilla #1736020 Certificate Misissuance

Telia CA: Invalid email contact address was used for few domains

RESOLVED FIXED Telia Company
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Telia CA reported that its previous email-based domain validation software could validate domains incorrectly, using an email target address for multiple unvalidated domains in the same request. Telia discovered the issue in internal routines related to email validation and determined it affected a small set of domains during 03–06/2020, with some certificates still valid at the time of discovery. Telia stated it had stopped creating illegal certificates after a change in the domain reuse period on 1 Oct 2021. Telia began revocation of affected certificates and reported that 2 of 7 illegal certificates were revoked/expired, while the remaining 5 were in critical, heavily used systems where Telia requested additional time to avoid major disturbance. Mozilla noted that a delayed revocation requires filing an additional incident report, and Telia created Bug 1737808 for the delayed revocation of 5 EE certificates. Telia later reported that all violating certificates were revoked (with a corrected date of October 29, 2021), and Mozilla indicated it would close the bug on February 16, 2022 unless further issues were raised. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 20:51 UTC Revised: 2026-06-16 18:16 UTC Confidence: 0.90 10 comments
Chronology
  1. Telia’s previous email-based domain validation software produced incorrect domain validation for a small set of domains (as later identified by Telia).
  2. Telia’s previous order validation software was closed October 2020 (as referenced by Telia).
  3. Telia’s change in domain reuse period expired problematic domains from early 2020, stopping creation of illegal certificates.
  4. Telia disclosed the issue in Bugzilla and described the affected certificates and planned revocation process.
  5. Telia created a separate delayed revocation incident report (Bug 1737808) for 5 EE certificates.
  6. Telia reported that all violating certificates were revoked (correcting the date).
  7. Mozilla planned to close the bug unless questions or issues remained.
Thread Activity
  1. Teliasonera representative — Telia described that invalid email domain validation occurred due to a bug in previous validation software, provided affected certificate/CT links, and stated it would revoke certificates still using illegally validated domains.
  2. Mm representative — A reviewer asked for clarification because two referenced certificates had only a single SAN, making the trigger unclear.
  3. Teliasonera representative — Telia clarified that the issue related to seven domains in three certificates and explained how pre-validated/reused validation led to inclusion of single-SAN certificates.
  4. Teliasonera representative — Telia reported alarm system implementation, system verification, renewal/closure of domains, and that 2/7 illegal certificates were revoked/expired while 5/7 were delayed due to critical usage.
  5. Mozilla representative — Mozilla stated that delayed revocation requires filing an additional incident report and referenced the whiteboard tags for the delayed-revocation leaf.
  6. Teliasonera representative — Telia stated it created Bug 1737808 for delayed revocation of 5 EE certificates related to this incident.
  7. Teliacompany representative — Telia reported that all violating certificates were revoked, then corrected the date to October 29, 2021.
  8. Mozilla representative — Mozilla said it would close the bug on February 16, 2022 unless there were questions or issues.
Participants
Teliasonera representative Mm representative Mozilla representative Teliacompany representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1674536 RESOLVED Certificate Misissuance Opened 2020-10-31 · Closed 2023-02-22 · 80% similar
Telia: Certificates with RSA keys where modulus is not divisible by 8
#1828105 RESOLVED Certificate Misissuance Opened 2023-04-14 · Closed 2023-06-30 · 77% similar
Telia: Misissued certificate - wrong OrganizationName value "Hair 8 Brains"
#1738207 RESOLVED Certificate Misissuance Opened 2021-10-28 · Closed 2023-02-22 · 75% similar
Telia: Issued three precertificates with non-NIST EC curve
#1737808 RESOLVED Delayed Revocation Opened 2021-10-26 · Closed 2023-02-22 · 74% similar
Telia: Delayed revocation of 5 EE certificates in connection to id=1736020
#1528259 RESOLVED Certificate Misissuance Opened 2019-02-15 · Closed 2023-02-22 · 70% similar
Telia: misissued certificate - FQDN value incorrectly in SAN rfc822 field
#1528261 RESOLVED Certificate Misissuance Opened 2019-02-15 · Closed 2023-02-22 · 70% similar
Telia: Misissued certificate - FQDN without domain part (e_dnsname_not_valid_tld)
#1528264 RESOLVED Certificate Misissuance Opened 2019-02-15 · Closed 2023-02-22 · 70% similar
Telia: Misissued certificate - Invalid OU value "-"
#1856591 RESOLVED Certificate Misissuance Opened 2023-10-03 · Closed 2024-01-26 · 69% similar
Telia: S/MIME certificates issued in violation of S/MIME BR v1.0.1

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action