Telekom Security delayed revocation of TLS certificates after basicConstraints misissuance
Telekom Security reported that 336 TLS certificates were not revoked within the 5-day deadline after it discovered they had been issued with basicConstraints present but not marked critical, which was described as a compliance issue tied to bug 1875820. The CA said affected customers were notified on 2024-01-22 and were asked to replace and revoke the certificates as soon as possible, but some customers said revocation would disrupt critical infrastructure. In response, Telekom Security initially delayed revocation for some certificates, then later said it revoked all remaining affected certificates and that all affected certificates were replaced and revoked by 2024-06-02. Mozilla and other commenters asked for a stronger root-cause analysis, per-subscriber explanations, and more concrete action items to prevent recurrence. Telekom Security later said it would add customer training, automation efforts, and annual self-assessments for Enterprise RAs, and the bug was resolved FIXED.
- Telekom Security identified affected certificates and notified customers to replace and revoke them within 5 days.
- The 5-day revocation period ended with 336 affected certificates still not revoked.
- Telekom Security decided to revoke all certificates that had not yet been revoked.
- All affected certificates were reported as replaced and revoked.
- Telekom representative — Telekom Security opened the bug and reported that 336 affected certificates were not revoked in time because some customers could not replace them within the deadline.
- Telekom representative — Telekom Security said it had now revoked all affected certificates that had not yet been revoked and listed the affected customer organisations and infrastructure types.
- Telekom representative — Telekom Security said it would offer more automation, training, workshops, and annual self-assessments for Enterprise RAs, and updated the timeline, root cause analysis, lessons learned, and action items.
- Telekom representative — Telekom Security said it was still working on the slides and self-assessment and expected to be ready by mid-May.
- Telekom representative — Telekom Security said it had finalized the training slides and self-assessment tasks and asked to close the bug if there were no further comments.
- Telekom representative — Telekom Security explained that it had given customers final deadlines, individual certificate lists, and daily status updates, and said it would continue to follow CA/Browser Forum discussions.
- Telekom representative — Telekom Security said it would review all comments again and provide further clarifications, and noted that it had already described a more detailed timeline, root cause analysis, and new action items.