← Deutsche Telekom Security GmbH cases
Bugzilla #1825780 Incident Self Reported Incident

Telekom Security: Improper use of a domain validation method

RESOLVED FIXED Deutsche Telekom Security GmbH
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

During an annual ETSI audit, Telekom Security identified that a domain validation method intended for internal customers could also be used by external customers, leading to a compliance issue. The CA took immediate action by halting the issuance of certificates using the questionable method and revoking 126 affected certificates. After further investigation, it was determined that the misunderstanding arose from misleading documentation. The CA has since implemented measures to ensure compliance and has committed to improving their validation processes. The case has been resolved with the CA acknowledging the non-conformity and taking corrective actions.

Model: gpt-4o-mini Generated: 2026-06-13 21:25 UTC Revised: 2026-06-16 18:34 UTC Confidence: 0.85 21 comments
Chronology
  1. Annual ETSI Audit revealed a compliance issue with domain validation.
  2. Last affected certificate was revoked.
  3. CA proposed closure of the bug after addressing all concerns.
Thread Activity
  1. Telekom representative — Initial report of compliance issue during the audit.
  2. Telekom representative — Clarified that the validation method was not used for external customers.
  3. Telekom representative — Confirmed the quality of random values generated by DENIC.
  4. Telekom representative — Proposed closure of the bug after addressing all feedback.
Participants
Telekom representative Mozilla representative Mm representative
External References
Similar Local Cases
#1875820 RESOLVED Incident Certificate Misissuance Self Reported Incident Opened 2024-01-22 · Closed 2024-08-03 · 100% similar
Telekom Security: TLS certificates with basicConstraints not marked as critical
#1675314 RESOLVED Self Reported Incident Opened 2020-11-04 · Closed 2023-02-22 · 95% similar
Telekom Security: Wrong jurisdiction entries in certificates
#1914383 RESOLVED Incident Certificate Misissuance Self Reported Incident Opened 2024-08-22 · Closed 2024-12-11 · 90% similar
Telekom Security: CRL-Entries with wrong CRL Reason Codes
#1651611 RESOLVED Self Reported Incident Opened 2020-07-09 · Closed 2023-02-22 · 87% similar
Telekom Security: Finding in 2020 ETSI-Audit regarding weekly review of changes to configurations
#1877388 RESOLVED Delayed Revocation Incident Self Reported Incident Opened 2024-01-30 · Closed 2025-03-14 · 86% similar
Telekom Security: Revocation delay for TLS certificates with basicConstraints not marked as critical
#1647084 RESOLVED Self Reported Incident Incident Opened 2020-06-20 · Closed 2023-02-22 · 85% similar
DigiCert / Microsoft: inconsistent disclosure of externally-operated intermediate
#1664328 RESOLVED Incident Self Reported Incident Opened 2020-09-10 · Closed 2023-02-22 · 80% similar
GlobalSign: SHA-256 hash algorithm used with ECC P-384 key
#1705832 RESOLVED Incident Self Reported Incident Opened 2021-04-16 · Closed 2023-02-22 · 79% similar
KIR S.A.: DV certificates with locality name, organization name and stateOrProvinceName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action