Telekom Security / DFN: CRL of “DFN-Verein Certification Authority 2” contains empty revokedCertificates list
The case concerns a CA/CRL compliance issue where the CRL for “DFN-Verein Certification Authority 2” contained the revokedCertificates element as an empty sequence within tbsCertList, even though there were no revoked certificates. The issue was disclosed as a third-party reported incident after Google Chrome informed Telekom Security about potential CA/Browser Forum TLS BR non-compliance on 2026-01-16. Telekom Security stated that DFN, as the operator of the externally operated Sub-CA, would submit the full incident report, while Telekom Security (as Root CA) remained responsible and worked closely with DFN. DFN’s investigation identified that a bug introduced during development of new CRL issuance software allowed empty revokedCertificates lists, and that CRL linting was not implemented in the affected PKI hierarchy. DFN issued compliant CRLs on 2026-01-22 for the listed CRL distribution points. The remediation described in the closure summary was to update the software, improve the software specification, and implement CRL linting; the bug was resolved as FIXED and the report closure requested completion of disclosed action items.
- DFN created the first non-compliant CRL using the new CRL issuance software component.
- Issuance in the affected PKI hierarchy stopped as part of discontinuation planning.
- Google Chrome informed Telekom Security about potential CA/Browser Forum TLS BR non-compliance related to CRL format.
- DFN issued compliant CRLs for the affected CRL distribution points.
- Mozilla bug status reached RESOLVED after the incident report closure process.
- Telekom representative — Filed a preliminary incident report stating the CRL contained revokedCertificates as an empty sequence and that this was third-party reported.
- Telekom representative — Explained that because the non-compliance originates from DFN-Verein Certification Authority 2 (an externally operated Sub-CA), DFN would submit the full incident report while Telekom Security would continue to work with DFN.
- Dfn-cert representative — Submitted the full incident report including the timeline, affected CRL distribution points, and root cause analysis (software specification/testing gaps and lack of CRL linting).
- Telekom representative — Requested setting the Next Update field to 20.02.2026 if no further questions/comments were received.
- Telekom representative — Indicated monitoring and asked to let them know if there were comments or questions.
- Dfn-cert representative — Reported completion of action item “Enhance depth of software specification” and listed remaining action items, including implementing CRL linting as ongoing at that time.
- Telekom representative — Requested setting the Next Update field to 2026-04-30 (due date of Actiom Item #4) if no further questions/comments were received.
- Dfn-cert representative — Reported “Implement CRL linting” completed and updated the action item table to show it as complete.
- Telekom representative — Provided the report closure summary stating the remediation (software update, improved specification, and CRL linting implementation) and requested closure after action items were completed.
- CCADB representative — Issued a final call for comments and stated the incident report would be closed approximately 2026-03-17.