Telekom Security: Transition Plan for Existing Dual-Purpose Roots
This case documents Telekom Security’s transition plan for existing dual-purpose roots after the inclusion of Telekom Security’s new TLS roots in the Chrome Root Store at the end of February. Telekom Security issued two cross-certificates from the TeleSec Global Root Class 3 to the Telekom Security TLS ECC Root 2020 and the Telekom Security TLS RSA Root 2023, and also issued new TLS Sub-CAs under the new TLS roots to support migrating TLS certificate issuance within the next two months. The plan states that the last TLS subscriber certificates issued under Telekom Security’s legacy Root CAs are expected to expire in April 2027, after which TLS certificates will chain exclusively to dedicated TLS roots. For S/MIME, Telekom Security expected to transition to dedicated S/MIME root CAs for issuing S/MIME certificates by the end of the year, with the last S/MIME certificates issued under “T-TeleSec Global Root Class 2” expected to expire in the fourth quarter of 2028. In a later update, Telekom Security adjusted the TLS transition plan to continue issuing TLS certificates for a small group of legacy applications that rely exclusively on the old Root CA “T-TeleSec GlobalRoot Class 2,” while transferring issuance to the new root CAs for other customers within two weeks. Telekom Security’s next step is to contact the Root Stores to remove the TLS trust bit for “T-Telesec GlobalRoot Class 2” by May 2027 (unless already planned).
- Telekom Security’s new TLS roots were included in the Chrome Root Store.
- Telekom Security issued cross-certificates and new TLS Sub-CAs to support migration to new TLS roots and described expected certificate expiry timelines for legacy roots.
- Telekom Security updated its TLS transition plan to keep limited legacy issuance under the old root and set a next step to remove the old root’s TLS trust bit by May 2027.
- Mozilla representative — Ben Wilson posted Telekom Security’s transition plan describing cross-certificates to new TLS roots, issuance of new TLS Sub-CAs, and expected expiry timelines for legacy TLS and S/MIME certificates.
- Telekom representative — Stefan Kirch stated Telekom Security would adjust the TLS transition plan to continue limited issuance for legacy applications relying on the old root, and said the next step is to contact Root Stores to remove the TLS trust bit for “T-Telesec GlobalRoot Class 2” by May 2027.