← Deutsche Telekom Security GmbH cases
Bugzilla #2011238
Certificate Problem Report
Telekom Security / DFN: CRL of “DFN-Verein Certification Authority 2“ contains empty revoked certificate list
RESOLVED
FIXED
Deutsche Telekom Security GmbH
AI Summary
The CRL for 'DFN-Verein Certification Authority 2' was found to contain an empty sequence for revoked certificates, which violates RFC 5280. This issue was reported by a third party and was identified on January 16, 2026. The non-compliance was addressed by issuing a compliant CRL on January 22, 2026, after the software responsible for generating the CRL was updated. The root causes included insufficient software specifications and the lack of CRL linting. All action items related to the incident have been completed, and the case is now resolved.
Chronology
- First non-compliant CRL created
- Non-compliance identified
- Compliant CRL issued
- Case resolved
Participants
Stefan Kirch
DFN PCA
External References
Similar Local Cases
Telekom Security: Root-CA certificates published in PEM encoded format
Telekom Security: CRL also contained unrevoked certificates
Telekom Security: CRL-Entries with wrong CRL Reason Codes
Telekom Security: TLS certificates with basicConstraints not marked as critical
Telekom Security: Multiple commonName in certificates
Telekom Security: Wrong jurisdiction entries in certificates
Deutsche telekom: no localityName or stateOrProvinceName
Telekom Security: Improper use of a domain validation method