← Deutsche Telekom Security GmbH cases
Bugzilla #2004668 Ca Certificate Compliance

Telekom Security: Root-CA certificates published in PEM encoded format

RESOLVED FIXED Deutsche Telekom Security GmbH
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Telekom Security reported an incident in which it had linked download points for issuing Root CA certificates in the AIA (“caIssuers”) of some Sub-CAs, but the Root CA certificates at those download points were encoded in PEM instead of DER as required by RFC 5280. The issue was identified after a third party reported the problem on 2025-12-06, and Telekom Security investigated it as a compliance incident affecting the Root CAs issued in 2008. Telekom Security remedied the problem by replacing the target files on all affected servers on 2025-12-08. The incident root cause was described as the people involved in publishing the CA certificates not being aware of the DER publication requirement because it was not explicitly mentioned in the work instructions. Telekom Security also updated its work instructions for commissioning CA certificates, with the action item marked complete by 2025-12-18. The incident report was later closed by CCADB after confirming that the action items were complete.

Model: gpt-5.4-nano Generated: 2026-06-13 21:29 UTC Revised: 2026-06-16 18:38 UTC Confidence: 0.86 10 comments
Chronology
  1. Telekom Security issued two Root CA certificates (T-TeleSec GlobalRoot Class 2 and Class 3) that were published for download.
  2. A third party reported that Root CA certificates referenced via AIA caIssuers were published in PEM rather than DER.
  3. Telekom Security replaced the affected server files so the Root CA certificates were provided in the required format.
  4. Telekom Security completed an update to work instructions for commissioning CA certificates.
  5. CCADB report closure summary was posted for the incident.
Thread Activity
  1. Telekom representative — Filed a preliminary incident report stating that Root CA certificates referenced in AIA caIssuers were PEM-encoded instead of DER.
  2. Telekom representative — Submitted the full incident report with details of the 2008 Root CAs, the RFC 5280 DER requirement, and the remediation timeline.
  3. Telekom representative — Reported an action item to update work instructions for commissioning CA certificates and marked it complete.
  4. Apple representative — Asked Telekom Security to confirm whether it monitors other CAs’ incident reports and how the issue was identified via third-party reporting.
  5. Telekom representative — Responded that it reviews CA Certificate Compliance bugs via a documented triage process and explained the third-party report timing over the weekend.
  6. Telekom representative — Noted monitoring for feedback and requested comments or questions.
  7. CCADB representative — Indicated all action items appeared complete and suggested filing a Closure Report if ready.
  8. Telekom representative — Posted the report closure summary describing the PEM-vs-DER issue, root cause, and remediation (server replacement next business day; work-instruction update within 2 weeks).
  9. CCADB representative — Issued a final call for comments or questions before closure.
Participants
Telekom representative Apple representative CCADB representative
Similar Local Cases
#2004733 RESOLVED Ca Certificate Compliance Opened 2025-12-08 · Closed 2026-01-15 · 78% similar
NAVER Cloud Trust Services: CA Certificate not published in DER Encoded Format
#1976860 RESOLVED Ca Certificate Compliance Opened 2025-07-11 · Closed 2025-08-21 · 76% similar
Telekom Security: Failure to file a bug for two findings from the 2024 Audit
#1957962 RESOLVED Ca Certificate Compliance Opened 2025-04-02 · Closed 2025-07-16 · 76% similar
Telekom Security: QCStatement with http link to PDS
#2047843 RESOLVED Ca Certificate Compliance Problem Reporting Failure Revocation Issue Opened 2026-06-16 · Closed 2026-07-09 · 69% similar
Certigna: Pre-certificates not recognised by the OCSP responder
#2007219 RESOLVED Ca Certificate Compliance Opened 2025-12-20 · Closed 2026-02-17 · 68% similar
DigiCert: Some certificates issued with CRLDPs that don’t exactly match CCADB disclosures
#2032485 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2026-04-16 · Closed 2026-05-04 · 68% similar
DigiCert: Misissuance detected by PKIMetal
#2015186 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2026-02-06 · Closed 2026-03-23 · 67% similar
DigiCert: Subject Serial Numbers for Non-Commercial Entities
#2007105 RESOLVED Ca Certificate Compliance Opened 2025-12-19 · Closed 2026-03-30 · 67% similar
Asseco DS / Certum: CRL URLs disclosed in CCADB do not exactly match the CRL URLs in certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action