← Deutsche Telekom Security GmbH cases
Bugzilla #1877388 Delayed Revocation Incident Self Reported Incident

Telekom Security delayed revocation of TLS certificates after basicConstraints misissuance

RESOLVED FIXED Deutsche Telekom Security GmbH
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Telekom Security reported that 336 TLS certificates were not revoked within the 5-day deadline after it discovered they had been issued with basicConstraints present but not marked critical, which was described as a compliance issue tied to bug 1875820. The CA said affected customers were notified on 2024-01-22 and were asked to replace and revoke the certificates as soon as possible, but some customers said revocation would disrupt critical infrastructure. In response, Telekom Security initially delayed revocation for some certificates, then later said it revoked all remaining affected certificates and that all affected certificates were replaced and revoked by 2024-06-02. Mozilla and other commenters asked for a stronger root-cause analysis, per-subscriber explanations, and more concrete action items to prevent recurrence. Telekom Security later said it would add customer training, automation efforts, and annual self-assessments for Enterprise RAs, and the bug was resolved FIXED.

Model: gpt-5.4-mini Generated: 2026-06-13 21:26 UTC Revised: 2026-06-16 17:28 UTC Confidence: 0.95 74 comments
Chronology
  1. Telekom Security identified affected certificates and notified customers to replace and revoke them within 5 days.
  2. The 5-day revocation period ended with 336 affected certificates still not revoked.
  3. Telekom Security decided to revoke all certificates that had not yet been revoked.
  4. All affected certificates were reported as replaced and revoked.
Thread Activity
  1. Telekom representative — Telekom Security opened the bug and reported that 336 affected certificates were not revoked in time because some customers could not replace them within the deadline.
  2. Telekom representative — Telekom Security said it had now revoked all affected certificates that had not yet been revoked and listed the affected customer organisations and infrastructure types.
  3. Telekom representative — Telekom Security said it would offer more automation, training, workshops, and annual self-assessments for Enterprise RAs, and updated the timeline, root cause analysis, lessons learned, and action items.
  4. Telekom representative — Telekom Security said it was still working on the slides and self-assessment and expected to be ready by mid-May.
  5. Telekom representative — Telekom Security said it had finalized the training slides and self-assessment tasks and asked to close the bug if there were no further comments.
  6. Telekom representative — Telekom Security explained that it had given customers final deadlines, individual certificate lists, and daily status updates, and said it would continue to follow CA/Browser Forum discussions.
  7. Telekom representative — Telekom Security said it would review all comments again and provide further clarifications, and noted that it had already described a more detailed timeline, root cause analysis, and new action items.
Participants
Telekom representative Daknob representative Community commenter Namepros representative Google representative Sectigo Mozilla representative Mailbox representative Mversen representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1875820 RESOLVED Incident Certificate Misissuance Self Reported Incident Opened 2024-01-22 · Closed 2024-08-03 · 97% similar
Telekom Security: TLS certificates with basicConstraints not marked as critical
#1651487 RESOLVED Delayed Revocation Opened 2020-07-08 · Closed 2023-02-22 · 95% similar
Telekom Security: Delayed Revocations of Sub-CA certificates
#1886110 RESOLVED Delayed Revocation Opened 2024-03-19 · Closed 2025-02-14 · 91% similar
TWCA: Revocation delay for TLS certificates with non-critical basicConstraints
#1889062 RESOLVED Delayed Revocation Opened 2024-04-02 · Closed 2025-04-03 · 90% similar
GDCA: Delayed revocation of SSL/TLS certificates with Non-critical Basic Constraints
#1887705 RESOLVED Delayed Revocation Opened 2024-03-25 · Closed 2024-09-12 · 88% similar
Entrust: Delayed revocation of clientAuth TLS Certificates without serverAuth EKU
#1887888 RESOLVED Delayed Revocation Opened 2024-03-26 · Closed 2025-02-28 · 88% similar
Hongkong Post: Delayed revocation of TLS certificates with basicConstraints not marked as critical
#1903066 RESOLVED Delayed Revocation Opened 2024-06-17 · Closed 2025-02-12 · 88% similar
Chunghwa Telecom: Delayed Revocation with Controversial Extension (2.5.29.9, SubjectDirectoryAttributes)
#1888882 RESOLVED Delayed Revocation Opened 2024-04-01 · Closed 2025-03-27 · 88% similar
CFCA: Delayed revocation of TLS certificates(basicConstraints extension not marked as critical)

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action