Telekom Security: TLS certificates with basicConstraints not marked as critical
Deutsche Telekom Security GmbH identified a compliance issue with TLS certificates issued by their TeleSec Business TLS-CA 2022, where the basicConstraints were not marked as critical, violating BR 7.1.2.7.6. This issue affected 816 certificates since September 15, 2023. Although the CA assessed that there were no security breaches or trust issues, they informed affected customers and requested revocation within five days. Due to feedback from critical infrastructure customers, they decided to delay revocation to allow more time for certificate replacement. All affected certificates were eventually revoked, and the CA has updated their compliance processes.
- Telekom Security discovered certificates with basicConstraints not marked as critical.
- Decision made to delay revocation for critical infrastructure certificates.
- All affected certificates were revoked.
- Telekom representative — Telekom Security has identified certificates with basicConstraints in the certificate that are not marked as critical.
- Telekom representative — Summary of the incident and impact on 816 TLS certificates provided.
- Telekom representative — Informed affected customers about the bug and decided to delay revocation for critical infrastructures.
- Telekom representative — The last certificates were revoked today, i.e. all certificates affected by this bug are revoked now.