← Deutsche Telekom Security GmbH cases
Bugzilla #1914383 Incident Certificate Misissuance Self Reported Incident

Telekom Security: CRL-Entries with wrong CRL Reason Codes

RESOLVED FIXED Deutsche Telekom Security GmbH
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Deutsche Telekom Security GmbH disclosed an incident involving the revocation of 762 TLS certificates with incorrect CRL reason codes. The revocations were necessary due to misissuance, but 298 certificates were revoked with reasons that did not comply with the Mozilla Root Store Policy. The CA identified that the failure to use the correct reason code 'superseded' was due to a lack of communication with Enterprise RA customers regarding revocation practices. A full incident report was provided, detailing the root cause and corrective actions taken, including updates to internal processes and staff training. All action items have been completed, and the CA is committed to preventing similar issues in the future.

Model: gpt-4o-mini Generated: 2026-06-13 21:27 UTC Revised: 2026-06-16 18:36 UTC Confidence: 0.85 25 comments
Chronology
  1. Preliminary incident report filed regarding incorrect CRL reason codes.
  2. Incident report closure summary submitted and all action items completed.
Thread Activity
  1. Telekom representative — Preliminary incident report filed regarding incorrect CRL reason codes.
  2. Telekom representative — Final incident report submitted detailing the revocation of 762 certificates.
  3. Telekom representative — Incident report closure summary submitted, confirming completion of all action items.
Participants
Community commenter
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
#1875820 RESOLVED Incident Certificate Misissuance Self Reported Incident Opened 2024-01-22 · Closed 2024-08-03 · 90% similar
Telekom Security: TLS certificates with basicConstraints not marked as critical
#1825780 RESOLVED Incident Self Reported Incident Opened 2023-03-31 · Closed 2023-07-05 · 90% similar
Telekom Security: Improper use of a domain validation method
#1703528 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-04-07 · Closed 2023-02-22 · 82% similar
Telekom Security: Key Encipherment in two ECC SAN TLS certificates
#1675314 RESOLVED Self Reported Incident Opened 2020-11-04 · Closed 2023-02-22 · 80% similar
Telekom Security: Wrong jurisdiction entries in certificates
#1705791 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-04-16 · Closed 2023-02-22 · 79% similar
Telekom Security: Multiple commonName in certificates
#1714193 RESOLVED Certificate Misissuance Self Reported Incident Opened 2021-06-02 · Closed 2023-02-22 · 78% similar
Sectigo: Incorrect locality information
#1711432 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-05-17 · Closed 2023-02-22 · 77% similar
Telekom Security: Certificate with invalid FQDN
#1651611 RESOLVED Self Reported Incident Opened 2020-07-09 · Closed 2023-02-22 · 77% similar
Telekom Security: Finding in 2020 ETSI-Audit regarding weekly review of changes to configurations

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action