← Deutsche Telekom Security GmbH cases
Bugzilla #1957962 Certificate Misissuance

Telekom Security: QCStatement with http link to PDS

RESOLVED FIXED Deutsche Telekom Security GmbH
AI Summary

Deutsche Telekom Security GmbH reported a misissuance of two test certificates where the QCStatement extension contained an http link instead of the required https link to the PKI Disclosure Statements (PDS). The certificates were never used in production and were revoked immediately upon discovery. The issue stemmed from insufficient quality assurance during the configuration of a new certificate management platform, which did not have the necessary linting rules to catch this error. Remedial actions include updating testing processes and contributing a pull request to enhance linting tools.

Model: gpt-4o-mini Generated: 2026-06-13 21:28 UTC Confidence: 0.95
Chronology
  1. First certificate issued on new platform
  2. Error discovered and certificates revoked
  3. Pull request for linting tool submitted
  4. Incident report closure summary submitted
Participants
Stefan Kirch Arnold Essing Adriano Santoni Dimitris Zacharos Inigo Barreira Pedro Fuentes
External References
Similar Local Cases
#1711432 RESOLVED Certificate Misissuance Opened 2021-05-17 · Closed 2023-02-22 · 57% similar
Telekom Security: Certificate with invalid FQDN
#1894560 RESOLVED Certificate Misissuance Opened 2024-05-01 · Closed 2024-07-03 · 47% similar
DigiCert: Incorrect case in Business Category
#1673119 RESOLVED Certificate Misissuance Opened 2020-10-23 · Closed 2023-02-22 · 47% similar
Entrust: Subscriber provides private key with CSR
#1534295 RESOLVED Certificate Misissuance Opened 2019-03-11 · Closed 2023-02-22 · 47% similar
Actalis: Insufficient serial number entropy
#1405817 RESOLVED Certificate Misissuance Opened 2017-10-04 · Closed 2023-02-22 · 46% similar
Actalis: Certs issued with same issuer and serial number
#1717357 RESOLVED Certificate Misissuance Opened 2021-06-20 · Closed 2023-02-22 · 45% similar
Actalis: Issuance of intermediates after 2020-08-20 that do not comply with Mozilla Policy and the Baseline Requirements
#1048045 RESOLVED Certificate Misissuance Opened 2014-08-03 · Closed 2022-11-14 · 42% similar
GlobalSign Partner: No SAN
#1644936 RESOLVED Certificate Misissuance Opened 2020-06-11 · Closed 2024-05-09 · 41% similar
Microsoft PKI Services: Certificate Mis-Issuance, Locality Missing

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action