← Deutsche Telekom Security GmbH cases
Bugzilla #2004668
Certificate Problem Report
Telekom Security: Root-CA certificates published in PEM encoded format
RESOLVED
FIXED
Deutsche Telekom Security GmbH
AI Summary
Telekom Security was found to have published Root CA certificates in PEM format instead of the required DER format, as specified in RFC 5280. This issue was identified through a third-party report and was resolved by replacing the incorrect files on the affected servers. The root cause was a lack of awareness regarding the encoding requirement among the personnel involved in the publication process. The incident was documented, and work instructions were updated to prevent future occurrences.
Chronology
- Issuance and publication of the two Root-CAs
- Non-compliance identified through third-party report
- Resolution of the issue by replacing target files
Participants
Stefan Kirch
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
Telekom Security: CRL-Entries with wrong CRL Reason Codes
Telekom Security / DFN: CRL of “DFN-Verein Certification Authority 2“ contains empty revoked certificate list
Telekom Security: TLS certificates with basicConstraints not marked as critical
Telekom Security: CRL also contained unrevoked certificates
Telekom Security: Multiple commonName in certificates
Telekom Security: Wrong jurisdiction entries in certificates
Telekom Security: Key Encipherment in two ECC SAN TLS certificates
TWCA: CA Certificate not published in DER Encoded Format