Telekom Security: Root-CA certificates published in PEM encoded format
Telekom Security reported an incident in which it had linked download points for issuing Root CA certificates in the AIA (“caIssuers”) of some Sub-CAs, but the Root CA certificates at those download points were encoded in PEM instead of DER as required by RFC 5280. The issue was identified after a third party reported the problem on 2025-12-06, and Telekom Security investigated it as a compliance incident affecting the Root CAs issued in 2008. Telekom Security remedied the problem by replacing the target files on all affected servers on 2025-12-08. The incident root cause was described as the people involved in publishing the CA certificates not being aware of the DER publication requirement because it was not explicitly mentioned in the work instructions. Telekom Security also updated its work instructions for commissioning CA certificates, with the action item marked complete by 2025-12-18. The incident report was later closed by CCADB after confirming that the action items were complete.
- Telekom Security issued two Root CA certificates (T-TeleSec GlobalRoot Class 2 and Class 3) that were published for download.
- A third party reported that Root CA certificates referenced via AIA caIssuers were published in PEM rather than DER.
- Telekom Security replaced the affected server files so the Root CA certificates were provided in the required format.
- Telekom Security completed an update to work instructions for commissioning CA certificates.
- CCADB report closure summary was posted for the incident.
- Telekom representative — Filed a preliminary incident report stating that Root CA certificates referenced in AIA caIssuers were PEM-encoded instead of DER.
- Telekom representative — Submitted the full incident report with details of the 2008 Root CAs, the RFC 5280 DER requirement, and the remediation timeline.
- Telekom representative — Reported an action item to update work instructions for commissioning CA certificates and marked it complete.
- Apple representative — Asked Telekom Security to confirm whether it monitors other CAs’ incident reports and how the issue was identified via third-party reporting.
- Telekom representative — Responded that it reviews CA Certificate Compliance bugs via a documented triage process and explained the third-party report timing over the weekend.
- Telekom representative — Noted monitoring for feedback and requested comments or questions.
- CCADB representative — Indicated all action items appeared complete and suggested filing a Closure Report if ready.
- Telekom representative — Posted the report closure summary describing the PEM-vs-DER issue, root cause, and remediation (server replacement next business day; work-instruction update within 2 weeks).
- CCADB representative — Issued a final call for comments or questions before closure.