← Deutsche Telekom Security GmbH cases
Bugzilla #1875820 Incident Certificate Misissuance Self Reported Incident

Telekom Security: TLS certificates with basicConstraints not marked as critical

RESOLVED FIXED Deutsche Telekom Security GmbH
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Deutsche Telekom Security GmbH identified a compliance issue with TLS certificates issued by their TeleSec Business TLS-CA 2022, where the basicConstraints were not marked as critical, violating BR 7.1.2.7.6. This issue affected 816 certificates since September 15, 2023. Although the CA assessed that there were no security breaches or trust issues, they informed affected customers and requested revocation within five days. Due to feedback from critical infrastructure customers, they decided to delay revocation to allow more time for certificate replacement. All affected certificates were eventually revoked, and the CA has updated their compliance processes.

Model: gpt-4o-mini Generated: 2026-06-13 21:25 UTC Revised: 2026-06-16 18:35 UTC Confidence: 0.85 16 comments
Chronology
  1. Telekom Security discovered certificates with basicConstraints not marked as critical.
  2. Decision made to delay revocation for critical infrastructure certificates.
  3. All affected certificates were revoked.
Thread Activity
  1. Telekom representative — Telekom Security has identified certificates with basicConstraints in the certificate that are not marked as critical.
  2. Telekom representative — Summary of the incident and impact on 816 TLS certificates provided.
  3. Telekom representative — Informed affected customers about the bug and decided to delay revocation for critical infrastructures.
  4. Telekom representative — The last certificates were revoked today, i.e. all certificates affected by this bug are revoked now.
Participants
Telekom representative Daknob representative Mozilla representative
External References
Similar Local Cases
#1825780 RESOLVED Incident Self Reported Incident Opened 2023-03-31 · Closed 2023-07-05 · 100% similar
Telekom Security: Improper use of a domain validation method
#1877388 RESOLVED Delayed Revocation Incident Self Reported Incident Opened 2024-01-30 · Closed 2025-03-14 · 97% similar
Telekom Security: Revocation delay for TLS certificates with basicConstraints not marked as critical
#1711432 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-05-17 · Closed 2023-02-22 · 94% similar
Telekom Security: Certificate with invalid FQDN
#1675314 RESOLVED Self Reported Incident Opened 2020-11-04 · Closed 2023-02-22 · 94% similar
Telekom Security: Wrong jurisdiction entries in certificates
#1914383 RESOLVED Incident Certificate Misissuance Self Reported Incident Opened 2024-08-22 · Closed 2024-12-11 · 90% similar
Telekom Security: CRL-Entries with wrong CRL Reason Codes
#1705791 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-04-16 · Closed 2023-02-22 · 90% similar
Telekom Security: Multiple commonName in certificates
#1703528 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-04-07 · Closed 2023-02-22 · 90% similar
Telekom Security: Key Encipherment in two ECC SAN TLS certificates
#1651611 RESOLVED Self Reported Incident Opened 2020-07-09 · Closed 2023-02-22 · 86% similar
Telekom Security: Finding in 2020 ETSI-Audit regarding weekly review of changes to configurations

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action