← Deutsche Telekom Security GmbH cases
Bugzilla #1914383
Certificate Problem Report
Telekom Security: CRL-Entries with wrong CRL Reason Codes
RESOLVED
FIXED
Deutsche Telekom Security GmbH
AI Summary
Telekom Security identified that 298 TLS certificates were revoked with incorrect CRL reason codes, violating section 4.9.1.1 of the TLS BRs. The required reason code 'superseded' was not applied to these certificates, leading to compliance issues. The root cause was a lack of communication regarding revocation procedures to Enterprise RA customers. Internal processes have since been updated, and staff training has been conducted to prevent future occurrences.
Chronology
- Preliminary incident report filed.
- Final incident report submitted.
- Incident report closure summary provided.
Participants
Arnold Essing
Stefan Kirch
Martijn Katerbarg
Dimitris Zacharopoulos
Ben Wilson
External References
Similar Local Cases
Telekom Security: CRL also contained unrevoked certificates
Telekom Security: TLS certificates with basicConstraints not marked as critical
Telekom Security: Improper use of a domain validation method
Telekom Security: Wrong jurisdiction entries in certificates
Telekom Security: Root-CA certificates published in PEM encoded format
Telekom Security: Key Encipherment in two ECC SAN TLS certificates
Telekom Security: Multiple commonName in certificates
certSIGN: Missing certificate from the list of bad order subject attributtes