← Telia Company cases
Bugzilla #1736020
Certificate Problem Report
Telia: Invalid email contact address was used for few domains
RESOLVED
FIXED
Telia Company
AI Summary
Telia Company identified an issue where an invalid email contact address was used for domain validation, leading to the issuance of certificates for domains that were not properly validated. This problem was discovered during internal audits and was traced back to a bug in their previous validation software used in early 2020. The CA has since revoked the affected certificates and implemented new systems to prevent similar issues in the future.
Chronology
- Discovery of invalid domain validation information.
- Incident reported to Mozilla.
- All violating certificates revoked.
Participants
pekka.lahtiharju@teliasonera.com
agwa-bugs@mm.beanwood.com
bwilson@mozilla.com
ali.gholami@teliacompany.com
External References
Similar Local Cases
Telia: Delayed revocation of 5 EE certificates in connection to id=1736020
Telia: Issued three precertificates with non-NIST EC curve
Telia: Certificates with RSA keys where modulus is not divisible by 8
Telia: AIA CA Issuer field pointing to PEM encoded cert
Telia: Two Intermediate CA certificates not listed in audit report
Google Trust Services: SXG certificates issued without correctly checking CAA restrictions
Microsoft PKI Services: CA Certificates not published in DER Encoded Format
Firmaprofesional: incorrect reserved CA/B Forum OIDs in certificates