← Deutsche Telekom Security GmbH cases
Bugzilla #1957962 Ca Certificate Compliance

Telekom Security: QCStatement with http link to PDS

RESOLVED FIXED Deutsche Telekom Security GmbH
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Deutsche Telekom Security GmbH self-reported an incident involving two misissued test certificates where the QCStatement extension contained an http link instead of the required https link to the PKI Disclosure Statements (PDS). The error was identified during audit preparations, and both certificates were immediately revoked as they had never been used in production. The CA has updated its internal processes to include additional linting checks and contributed a pull request to the zlint tool to prevent similar issues in the future. The incident has been resolved with all action items completed.

Model: gpt-4o-mini Generated: 2026-06-13 21:28 UTC Revised: 2026-06-16 18:36 UTC Confidence: 0.90 18 comments
Chronology
  1. First certificate of the type was issued on the new platform.
  2. Error found and both certificates revoked.
  3. All action items completed and incident reported closure requested.
Thread Activity
  1. Telekom representative — Preliminary Incident Report filed regarding the misissued certificates.
  2. Telekom representative — Full Incident Report provided detailing the misissuance and corrective actions.
  3. Telekom representative — Request for closure of the bug as all action items have been completed.
Participants
Telekom representative CCADB representative
External References
Similar Local Cases
#1976860 RESOLVED Ca Certificate Compliance Opened 2025-07-11 · Closed 2025-08-21 · 96% similar
Telekom Security: Failure to file a bug for two findings from the 2024 Audit
#1703528 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-04-07 · Closed 2023-02-22 · 91% similar
Telekom Security: Key Encipherment in two ECC SAN TLS certificates
#1705791 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-04-16 · Closed 2023-02-22 · 88% similar
Telekom Security: Multiple commonName in certificates
#1711432 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-05-17 · Closed 2023-02-22 · 87% similar
Telekom Security: Certificate with invalid FQDN
#2004668 RESOLVED Ca Certificate Compliance Opened 2025-12-08 · Closed 2026-01-20 · 76% similar
Telekom Security: Root-CA certificates published in PEM encoded format
#1963456 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-04-29 · Closed 2025-07-25 · 70% similar
GoDaddy: CA Certificates with HTTPS URL in AIA Field
#1986968 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-09-04 · Closed 2026-04-06 · 69% similar
Financijska agencija (Fina): Mis-issued certificates
#2005567 RESOLVED Ca Certificate Compliance Opened 2025-12-11 · Closed 2026-02-03 · 69% similar
Chunghwa Telecom: CA Certificates Published in PEM format

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action