Telekom Security: Improper use of a domain validation method
During an annual ETSI audit, Telekom Security identified that a domain validation method intended for internal customers could also be used by external customers, leading to a compliance issue. The CA took immediate action by halting the issuance of certificates using the questionable method and revoking 126 affected certificates. After further investigation, it was determined that the misunderstanding arose from misleading documentation. The CA has since implemented measures to ensure compliance and has committed to improving their validation processes. The case has been resolved with the CA acknowledging the non-conformity and taking corrective actions.
- Annual ETSI Audit revealed a compliance issue with domain validation.
- Last affected certificate was revoked.
- CA proposed closure of the bug after addressing all concerns.
- Telekom representative — Initial report of compliance issue during the audit.
- Telekom representative — Clarified that the validation method was not used for external customers.
- Telekom representative — Confirmed the quality of random values generated by DENIC.
- Telekom representative — Proposed closure of the bug after addressing all feedback.