← Deutsche Telekom Security GmbH cases
Bugzilla #1877388 Delayed Revocation

Telekom Security: Revocation delay for TLS certificates with basicConstraints not marked as critical

RESOLVED FIXED Deutsche Telekom Security GmbH
AI Summary

Telekom Security faced a significant incident involving the delayed revocation of 336 TLS certificates that were issued without marking the basicConstraints as critical. The delay was attributed to the critical nature of the infrastructures relying on these certificates, which led to a decision not to enforce revocation within the required timeframe. The CA has since taken steps to sensitize customers about the importance of timely certificate replacement and has implemented self-assessments and audits to ensure compliance with revocation deadlines in the future. Despite these measures, concerns remain regarding the CA's commitment to adhering strictly to the Baseline Requirements in future incidents.

Model: gpt-4o-mini Generated: 2026-06-13 21:26 UTC Confidence: 0.90
Chronology
  1. Affected customers were informed about the need to revoke certificates.
  2. End of the 5-day period for revocation; 336 certificates were not revoked.
  3. Incident report opened.
  4. All affected certificates were replaced and revoked.
  5. Closure summary provided for the incident.
Participants
Arnold Essing Tim Callan Mike Shaver Ben Wilson
Similar Local Cases
#1887110 RESOLVED Delayed Revocation Opened 2024-03-22 · Closed 2025-02-14 · 63% similar
Microsec: Delayed revocation of the misissued certificates
#1872738 RESOLVED Delayed Revocation Opened 2024-01-02 · Closed 2025-02-14 · 62% similar
Buypass: Delayed revocation of TLS certificates
#1886665 RESOLVED Delayed Revocation Opened 2024-03-21 · Closed 2025-02-28 · 60% similar
Hongkong Post: Delayed revocation of TLS certificates with Certificate Policies extension problem
#1887888 RESOLVED Delayed Revocation Opened 2024-03-26 · Closed 2025-02-28 · 59% similar
Hongkong Post: Delayed revocation of TLS certificates with basicConstraints not marked as critical
#1651487 RESOLVED Delayed Revocation Opened 2020-07-08 · Closed 2023-02-22 · 57% similar
Telekom Security: Delayed Revocations of Sub-CA certificates
#1887705 RESOLVED Delayed Revocation Opened 2024-03-25 · Closed 2024-09-12 · 55% similar
Entrust: Delayed revocation of clientAuth TLS Certificates without serverAuth EKU
#1896053 RESOLVED Delayed Revocation Opened 2024-05-10 · Closed 2025-07-16 · 51% similar
Digicert: Delayed Revocation for bug 1894560
#1707229 RESOLVED Delayed Revocation Opened 2021-04-23 · Closed 2023-02-22 · 50% similar
SECOM: Delayed Revocation of non-technically constrained FUJIFILM Certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action