Telia: TLS incorrect AIA caIssuer URI and incorrect CDP (self-reported incident report)
Telia reported a self-discovered incident in which Telia CA issued 15 TLS subscriber certificates with incorrect certificate extension contents for Authority Information Access (id-ad-caIssuers) and CRL Distribution Points (distributionPoint). The incorrect values caused the issued certificates to contain URIs pointing to the wrong CA Issuer certificate and CA Issuer CRL. Telia stated the non-compliance started on 2025-05-27 and was identified on 2025-05-28, with the non-compliance ending on 2025-05-28. Telia said it did not stop issuance, because the issue was corrected after the Telia CA PKI team identified it and updated the issuing CA policy to correct the incorrect URIs. Telia also reported that affected certificates were identified, subscribers were informed about the revocation requirement, and the certificates were revoked as soon as possible and within 24 hours of issuance. In later updates, Telia reported completion of action items including CA policy management refresh training and implementing custom pre-issuance linting to prevent this type of issue. The bug was resolved with resolution set to FIXED.
- Telia CA began issuing TLS subscriber certificates with incorrect AIA caIssuer and CDP values due to an issuing CA policy update.
- Telia identified the non-compliance and corrected the issuing CA policy; affected certificates were subsequently revoked.
- Telia reported custom pre-issuance linting was implemented in production to prevent this issue type.
- Bug status was updated to RESOLVED with resolution FIXED.
- Teliacompany representative — Filed a preliminary incident report describing 15 misissued TLS subscriber certificates with incorrect AIA caIssuer and CDP URIs, and stated the source of disclosure was self-reported.
- Teliacompany representative — Submitted the full incident report with the same incident description, timeline, impact, and self-reported disclosure source.
- Teliacompany representative — Reported completion of the CA policy management refresh training action item and requested a next update date for a remaining action item.
- Teliacompany representative — Reported that custom pre-issuance linting was implemented in production and marked the action items as completed.
- Teliacompany representative — Provided a report closure summary including root causes, remediation steps, and stated that all action items were completed and closure was requested.
- CCADB representative — Issued a final call for comments and indicated the incident report would be closed around 2025-07-14.
- Teliacompany representative — Updated the next update request and stated they were waiting for the incident to be closed as indicated in a prior comment.