Telekom Security: CRL-Entries with wrong CRL Reason Codes
Deutsche Telekom Security GmbH disclosed an incident involving the revocation of 762 TLS certificates with incorrect CRL reason codes. The revocations were necessary due to misissuance, but 298 certificates were revoked with reasons that did not comply with the Mozilla Root Store Policy. The CA identified that the failure to use the correct reason code 'superseded' was due to a lack of communication with Enterprise RA customers regarding revocation practices. A full incident report was provided, detailing the root cause and corrective actions taken, including updates to internal processes and staff training. All action items have been completed, and the CA is committed to preventing similar issues in the future.
- Preliminary incident report filed regarding incorrect CRL reason codes.
- Incident report closure summary submitted and all action items completed.
- Telekom representative — Preliminary incident report filed regarding incorrect CRL reason codes.
- Telekom representative — Final incident report submitted detailing the revocation of 762 certificates.
- Telekom representative — Incident report closure summary submitted, confirming completion of all action items.