← Deutsche Telekom Security GmbH cases
Bugzilla #1825780
Certificate Problem Report
Telekom Security: Improper use of a domain validation method
RESOLVED
FIXED
Deutsche Telekom Security GmbH
AI Summary
During an annual ETSI audit, Telekom Security identified that a domain validation method intended for internal customers was also accessible to external customers. This misunderstanding stemmed from misleading documentation, leading to immediate actions including halting certificate issuance and revoking affected certificates. After further investigation, it was confirmed that the validation method was not compliant with the Baseline Requirements, prompting a commitment to improve auditing processes. The case was resolved with the method being permanently discontinued.
Chronology
- Non-conformity identified during annual ETSI audit.
- Last affected certificate revoked.
- Final consultation with auditor; misunderstanding clarified.
- Bug closed.
Participants
Arnold Essing
Jan Voelkel
Ben Wilson
External References
Similar Local Cases
Telekom Security: CRL-Entries with wrong CRL Reason Codes
Telekom Security: Wrong jurisdiction entries in certificates
Telekom Security: Multiple commonName in certificates
Telekom Security: Key Encipherment in two ECC SAN TLS certificates
Telekom Security: CRL also contained unrevoked certificates
Telekom Security: TLS certificates with basicConstraints not marked as critical
GlobalSign: Failure to revoke noncompliant ICA within 7 days
Telekom Security / DFN: CRL of “DFN-Verein Certification Authority 2“ contains empty revoked certificate list