← Deutsche Telekom Security GmbH cases
Bugzilla #1976860 Ca Certificate Compliance

Telekom Security: Failure to file a bug for two findings from the 2024 Audit

RESOLVED FIXED Deutsche Telekom Security GmbH
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Telekom Security GmbH disclosed that, during an ETSI audit in 2024, its auditors identified two findings that were already resolved during the audit, but Telekom Security failed to file a Bugzilla bug for them. Telekom Security stated that it overlooked the list of findings in the Audit Attestations, which it described as the decisive documents, and that it initially interpreted the findings as not requiring a bug because it believed there was no violation and only insufficient internal documentation. After a Root Store request on 2025-07-10 asking why the findings were not disclosed in a bug, Telekom Security disclosed a preliminary bug on 2025-07-11 and then provided a full incident report in this bug on 2025-07-17. The incident report describes two findings related to (1) documentation and implementation of a role appointment and access right process and (2) documentation and implementation of subcontractor management. Telekom Security provided action items to finalize documentation and to sensitize employees, and later stated that it completed the action items. The bug was requested for closure after all action items were completed, and CCADB indicated it would be closed on approximately 2025-08-20 if no further comments or questions were raised.

Model: gpt-5.4-nano Generated: 2026-06-13 21:28 UTC Revised: 2026-06-16 18:37 UTC Confidence: 0.86 8 comments
Chronology
  1. ETSI audit attestations were published identifying two findings.
  2. A Root Store requested why Telekom Security did not disclose the audit findings in a bug.
  3. Telekom Security disclosed a preliminary incident bug in Bugzilla.
  4. Telekom Security disclosed the full incident report in the bug.
  5. Telekom Security stated it completed the action item to adapt audit and incident management processes and documentation.
  6. Telekom Security requested closure after completing all action items.
Thread Activity
  1. Telekom representative — Opened the preliminary incident report stating Telekom Security failed to file a bug for two findings from the 2024 Audit and cited the relevant policies.
  2. Telekom representative — Provided the full incident report, explaining the two audit findings, why a bug was not filed initially, and the timeline including the Root Store request.
  3. Google representative — Requested additional detail on root cause analysis and action items, noting the report did not describe RCA/action items in the expected way.
  4. Telekom representative — Responded to feedback, provided an Audit Incident Report structure for both findings including root cause analysis and action items.
  5. Telekom representative — Reported completion of the action items and their statuses.
  6. Telekom representative — Submitted a report closure summary and requested closure, stating all action items were completed.
  7. CCADB representative — Issued a final call for comments or questions and stated the bug would be closed on approximately 2025-08-20.
Participants
Telekom representative Google representative CCADB representative
Similar Local Cases
#1957962 RESOLVED Ca Certificate Compliance Opened 2025-04-02 · Closed 2025-07-16 · 96% similar
Telekom Security: QCStatement with http link to PDS
#1711432 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-05-17 · Closed 2023-02-22 · 78% similar
Telekom Security: Certificate with invalid FQDN
#1703528 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-04-07 · Closed 2023-02-22 · 78% similar
Telekom Security: Key Encipherment in two ECC SAN TLS certificates
#1705791 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-04-16 · Closed 2023-02-22 · 77% similar
Telekom Security: Multiple commonName in certificates
#2004668 RESOLVED Ca Certificate Compliance Opened 2025-12-08 · Closed 2026-01-20 · 76% similar
Telekom Security: Root-CA certificates published in PEM encoded format
#1950574 RESOLVED Ca Certificate Compliance Incident Revocation Issue Opened 2025-02-26 · Closed 2025-09-15 · 75% similar
SECOM: S/MIME CA Modified Opinion Report of Cybertrust Japan (CTJ)
#1983955 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2025-08-19 · Closed 2025-09-15 · 75% similar
Certigna: Subscriber certificate with EKU clientAuth only
#2004732 RESOLVED Ca Certificate Compliance Incident Opened 2025-12-08 · Closed 2026-01-05 · 75% similar
Certigna: AIA CA issuer field pointing to PEM encoded cert

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action